CVE-2026-89924
Last modified
CVE-2026-89924 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully.
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 27291e2165b6de70c476b7b675308113edd69a60, < 124c81ee610e1fbdd93d4399f88d9e28ba97a941; >= 27291e2165b6de70c476b7b675308113edd69a60, < e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4; >= 27291e2165b6de70c476b7b675308113edd69a60, < c85d402553987777cc4742751437ea5dcbf98a7b; >= 27291e2165b6de70c476b7b675308113edd69a60, < 5fbf319137735252eefa507193c9a619af5b7457; >= 27291e2165b6de70c476b7b675308113edd69a60, < 4048d0a252163084794be3e37995b872c5178913; >= 27291e2165b6de70c476b7b675308113edd69a60, < f55e4d415d95342d5753e528e05a1e8623992c3f; >= 27291e2165b6de70c476b7b675308113edd69a60, < 46cb8a273e2f853f89a78b59dbdff8787b6e1c86; >= 27291e2165b6de70c476b7b675308113edd69a60, < aa9c8e8baf1e765fa65b93212522c636f25d846f |
| Linux | Linux | 3.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89924?
How severe is CVE-2026-89924?
How do I fix CVE-2026-89924?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89919In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8992An improper certificate validation vulnerability in Ivanti S…8.8
- CVE-2026-89920In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89921In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89922In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89923In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89925In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89926In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89927In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-89928In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89929In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-8993D.Launcher 2 component of Slovak eID client ecosystem contai…6.5
Are you affected by CVE-2026-89924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
