CVE-2026-89955
Last modified
CVE-2026-89955 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix NULL deref in status_show() during queue probe When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group().
Description
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix NULL deref in status_show() during queue probe When vfio_ap_mdev_probe_queue() creates the sysfs attribute group, the queue's driver data has not yet been set. A concurrent read of the 'status' attribute can therefore call dev_get_drvdata() and get NULL, which is then passed directly to vfio_ap_mdev_for_queue() where q->apqn is unconditionally dereferenced, causing a NULL pointer dereference. Fix this by acquiring the update locks before calling sysfs_create_group(). The status_show() function acquires guests_lock before reading the driver data, so any concurrent read will block until after dev_set_drvdata() has been called and the update locks are released. As a bonus, the APQN no longer needs to be read from the queue struct after allocation — it can be read directly from apdev before allocation and stored in a local variable, which is then assigned to q->apqn once the allocation succeeds.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 260f3ea141382386e97611e7c2029bc013088ab1, < 31fa0a8a3c337ed2d200166d6926ab23c14f8b2e; >= 260f3ea141382386e97611e7c2029bc013088ab1, < e102ce0f4af99dff769a4b1b4daa4cc6bd5ad2d9; >= 260f3ea141382386e97611e7c2029bc013088ab1, < 69632952aca04caa71e49953b6949fc04e788e67; >= 260f3ea141382386e97611e7c2029bc013088ab1, < 7db2511fc601ca3a6e3fb1bdce02261c3c3167c3; >= 260f3ea141382386e97611e7c2029bc013088ab1, < dd6f4ef6f8a37412909ad787c837332fb070159c |
| Linux | Linux | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89955?
How severe is CVE-2026-89955?
How do I fix CVE-2026-89955?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8995The Poll Maker – Versus Polls, Anonymous Polls, Image Polls …4.3
- CVE-2026-89950In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89951In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89952In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89953In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89954In the Linux kernel, the following vulnerability has been re…8
- CVE-2026-89956In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89957In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89958In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89959In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-8996The Backup and Staging by WP Time Capsule plugin for WordPre…6.5
- CVE-2026-89960In the Linux kernel, the following vulnerability has been re…8.8
Are you affected by CVE-2026-89955?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
