CVE-2026-89922

HIGHCVSS 7.8/10

Last modified

CVE-2026-89922 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import..

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.

Metrics

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 27291e2165b6de70c476b7b675308113edd69a60, < 6830fbc3724bf49c142aae69a4694f115fa9cedd; >= 27291e2165b6de70c476b7b675308113edd69a60, < f8e3a9997d5ecd56ebe4b262ff424516c068fecb; >= 27291e2165b6de70c476b7b675308113edd69a60, < 76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03; >= 27291e2165b6de70c476b7b675308113edd69a60, < cc710ee45395efb4937e042960f791d33924e5f6; >= 27291e2165b6de70c476b7b675308113edd69a60, < 4c05bf21d1806853e662cc19e744736a3408f155; >= 27291e2165b6de70c476b7b675308113edd69a60, < a4e482def8533ebace517d9f67f1465841b1f982
LinuxLinux3.16

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89922?
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot update can free the memslots array under us once its SRCU grace period has elapsed. As this is not fast path, following lock ordering (mutex first, then srcu) take the big hammer and hold the srcu for the full import.
How severe is CVE-2026-89922?
CVE-2026-89922 has a CVSS score of 7.8/10 (HIGH severity).
How do I fix CVE-2026-89922?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89922?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST