PatchSiren cyber security CVE debrief
CVE-2026-89795 Linux CVE debrief
A vulnerability in the Linux kernel has been resolved, affecting PCI slot reset on s390 systems. The issue arises from the current implementation of pci_create_slot(), which assigns the same pci_slot object to multifunction devices. This causes problems when resetting a function through the hotplug driver's slot_reset() interface, leading to the wrong function being reset and memory leaks.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-03
Who should care
Linux kernel maintainers, users, and administrators of s390 systems should assess exposure and verify affected versions. They should review and apply patches from the Linux kernel maintainers, monitor system logs for potential exploitation attempts, and review compensating controls for exposed systems.
Why it matters
The vulnerability affects PCI slot reset on s390 systems, which use a machine level hypervisor. Linux kernel maintainers and users should assess exposure and verify affected versions.
- Verify affected versions and assess exposure
- Apply patches from the Linux kernel maintainers
- Monitor system logs for potential exploitation attempts
Technical summary
The Linux kernel vulnerability affects PCI slot reset on s390 systems, which use a machine level hypervisor. The issue arises from the current implementation of pci_create_slot(), which assigns the same pci_slot object to multifunction devices. This causes problems when resetting a function through the hotplug driver's slot_reset() interface, leading to the wrong function being reset and memory leaks. Linux kernel maintainers and users should assess exposure and verify affected versions to address this vulnerability.
Defensive priority
Linux kernel maintainers and users should assess exposure and verify affected versions.
Recommended defensive actions
- Assess exposure and verify affected versions
- Review and apply patches from the Linux kernel maintainers
- Monitor system logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability. However, the corpus does not establish versions, exploitation, impact, or remediation, which require verification from the supplied official sources. Linux kernel maintainers and users should verify affected versions, assess exposure, and review patches. The vulnerability affects PCI slot reset on s390 systems, which use a machine level hypervisor.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89795 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89795
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89795 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89795
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0d1a7d67f45645106578d65181e4e492dd20ed79
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2050d900f9adbd6d6f38d30e182bcd9ad3108467
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dcc5bec09e23bbc4f9de055a11fce9937244f2c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ecdcceed4d377b02d4ea036b65f83f962c38ede7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.