CVE-2026-80921

HIGHCVSS 8.8/10

Last modified

CVE-2026-80921 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available.

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < d110b3297f11ef227098b8a82ade2d5f123b7d2f; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 59d51550b5cb916bda037673a721a404b3b47a0d; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < f6079dca67eccb5eabef9f72437948c66dc5131f; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 087c19cc60a8caa1a08e1e434c8be2caf6c27733; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 7d23489f51109e3ebba5b5db8c5f0185af7b7fdf; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 935eeba276012916c76243e5cbb843efd8fdb75d; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < d4bcd2df6d0d2af916b4fe1a533958778ea7c45b; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6; >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, < 34d5b5b646c91cfb9338d7a12c955a70ffb8c66b
LinuxLinux4.20

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-80921?
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
How severe is CVE-2026-80921?
CVE-2026-80921 has a CVSS score of 8.8/10 (HIGH severity).
How do I fix CVE-2026-80921?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-80921?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST