PatchSiren cyber security CVE debrief
CVE-2026-52968 Linux CVE debrief
A vulnerability was found in the Linux kernel's KVM: s390: pci subsystem. The flaw in GAIT table indexing due to double-scaling pointer arithmetic can cause out-of-bounds accesses when aisb >= 32. This issue affects Linux kernel users, particularly those with KVM: s390: pci deployments. The vulnerability was resolved by removing the erroneous sizeof multiplication. To mitigate the risk, users should review and apply the official patch. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-07-18
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-07-18
Who should care
Linux kernel users, KVM administrators, and s390 system operators should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review and apply the official patch, update KVM configurations to ensure secure operation, and monitor system logs for potential exploitation attempts. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes.
Technical summary
The vulnerability is caused by incorrect pointer arithmetic in the kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() functions. The aift->gait pointer is already a struct zpci_gaite pointer, but the code multiplies the index by sizeof(struct zpci_gaite), resulting in double-scaling and out-of-bounds accesses. This issue can be fixed by removing the erroneous sizeof multiplication. The official patches are available, and users are advised to apply them to prevent potential attacks. The vulnerability affects Linux kernel users, particularly those with KVM: s390: pci deployments.
Defensive priority
High priority for Linux kernel maintainers and KVM administrators to apply the fix and prevent potential attacks.
Recommended defensive actions
- Apply the official patch to fix the vulnerability
- Review and update KVM configurations to ensure secure operation
- Monitor system logs for potential exploitation attempts
- Perform a thorough review of the system to ensure the vulnerability is not being exploited
- Consider implementing compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was resolved by removing the erroneous sizeof multiplication. Official patches are available at https://git.kernel.org/stable/c/11b8ff5b930b351dd1f6f088dce0beb027ac92d0 and other referenced commits. The vulnerability affects Linux kernel users, particularly those with KVM: s390: pci deployments. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes. Users should verify the patch and ensure it is applied correctly to prevent potential attacks.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-52968 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-52968
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-52968 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52968
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/11b8ff5b930b351dd1f6f088dce0beb027ac92d0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/16d990a15491cf76cd6eef0846e1b4100e63261a
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/31a9d9f9942885aae356a1a57c79e82c5b5b0828
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a99a25db131ece5e6c0f7632da606de631efe4f2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b22a2da8792a7bfe743c1a922e77fa499ddedbe8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e7216651b94e92e5433fb2f54b77864642b4ea48
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.