PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89921 Linux CVE debrief

A Linux kernel vulnerability allows a host user to access sensitive data through migration ioctls, although guest data remains secure. The issue arises from the __kvm_inject_pfault_token() function not fully initializing the on-stack struct kvm_s390_irq, leading to stale stack values in ext_params and pad. This information can be obtained by a host user using migration ioctls.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-03
Advisory published
2026-09-16
Advisory updated
2026-10-03

Who should care

Linux kernel maintainers, KVM administrators, and security teams responsible for Linux-based virtualization infrastructure should assess exposure and prioritize remediation. This includes verifying Linux kernel versions and KVM configurations, reviewing system migration ioctls restrictions, and applying Linux kernel updates addressing CVE-2026-89921. Additionally, they should perform vulnerability assessments and inventory affected systems for remediation.

Why it matters

CVE-2026-89921 is a Linux kernel vulnerability that allows a host user to access sensitive data through migration ioctls. Although guest data remains secure, Linux kernel maintainers, KVM administrators, and security teams should assess exposure and prioritize remediation. The issue is resolved in the Linux kernel, and four source references provide details on the specific commits that address the issue.

  • Host users can access sensitive data through migration ioctls
  • Requires verification of Linux kernel versions and KVM configurations
  • Remediation involves applying Linux kernel updates
  • Exposure assessment is necessary for Linux-based virtualization infrastructure

Technical summary

The __kvm_inject_pfault_token() function in the Linux kernel does not fully initialize the on-stack struct kvm_s390_irq, leading to sensitive data exposure through migration ioctls. The issue is resolved by zero-initializing the irq struct. This vulnerability allows a host user to access sensitive data, although guest data remains secure. Linux kernel maintainers, KVM administrators, and security teams should assess exposure and prioritize remediation for Linux kernel deployments using KVM on s390 architectures, focusing on verifying system migration ioctls restrictions and applying Linux kernel updates.

Defensive priority

Assess exposure and prioritize remediation for Linux kernel deployments using KVM on s390 architectures.

Recommended defensive actions

  • Assess Linux kernel versions and KVM configurations for potential exposure
  • Verify system migration ioctls are properly restricted
  • Review and apply Linux kernel updates addressing CVE-2026-89921
  • Monitor system logs for suspicious migration ioctl activity
  • Perform vulnerability assessment for Linux-based virtualization infrastructure
  • Inventory and track affected systems for remediation prioritization
  • Review compensating controls for exposed systems while remediation is scheduled

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, which is resolved in the Linux kernel. Four source references are provided, detailing the specific commits that address the issue. To verify, defenders should review Linux kernel versions and KVM configurations for potential exposure, and assess the migration ioctls restrictions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89921 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89921

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89921 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89921

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/134f235e0e8de54611a72d3cc3f63e5f31246baa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4e2c7f7cbc27418f9a290399b986c1b85ff93b90

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9b046de62b8098af6e2ba820b125ec9dc5f162c8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b8abc760fa18a389319d977834a30550b3ec18e8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.