PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-52968 Linux CVE debrief

A vulnerability was found in the Linux kernel's KVM: s390: pci subsystem. The flaw in GAIT table indexing due to double-scaling pointer arithmetic can cause out-of-bounds accesses when aisb >= 32. This issue affects Linux kernel users, particularly those with KVM: s390: pci deployments. The vulnerability was resolved by removing the erroneous sizeof multiplication. To mitigate the risk, users should review and apply the official patch. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-24
Original CVE updated
2026-07-18
Advisory published
2026-06-24
Advisory updated
2026-07-18

Who should care

Linux kernel users, KVM administrators, and s390 system operators should be aware of this vulnerability and take necessary actions to mitigate the risk. They should review and apply the official patch, update KVM configurations to ensure secure operation, and monitor system logs for potential exploitation attempts. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes.

Technical summary

The vulnerability is caused by incorrect pointer arithmetic in the kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() functions. The aift->gait pointer is already a struct zpci_gaite pointer, but the code multiplies the index by sizeof(struct zpci_gaite), resulting in double-scaling and out-of-bounds accesses. This issue can be fixed by removing the erroneous sizeof multiplication. The official patches are available, and users are advised to apply them to prevent potential attacks. The vulnerability affects Linux kernel users, particularly those with KVM: s390: pci deployments.

Defensive priority

High priority for Linux kernel maintainers and KVM administrators to apply the fix and prevent potential attacks.

Recommended defensive actions

  • Apply the official patch to fix the vulnerability
  • Review and update KVM configurations to ensure secure operation
  • Monitor system logs for potential exploitation attempts
  • Perform a thorough review of the system to ensure the vulnerability is not being exploited
  • Consider implementing compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability was resolved by removing the erroneous sizeof multiplication. Official patches are available at https://git.kernel.org/stable/c/11b8ff5b930b351dd1f6f088dce0beb027ac92d0 and other referenced commits. The vulnerability affects Linux kernel users, particularly those with KVM: s390: pci deployments. The vulnerability has a high impact on system security, and its exploitation could lead to unauthorized access or system crashes. Users should verify the patch and ensure it is applied correctly to prevent potential attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-52968 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-52968

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-52968 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-52968

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/11b8ff5b930b351dd1f6f088dce0beb027ac92d0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/16d990a15491cf76cd6eef0846e1b4100e63261a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/31a9d9f9942885aae356a1a57c79e82c5b5b0828

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a99a25db131ece5e6c0f7632da606de631efe4f2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b22a2da8792a7bfe743c1a922e77fa499ddedbe8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e7216651b94e92e5433fb2f54b77864642b4ea48

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.