PatchSiren cyber security CVE debrief
CVE-2026-89921 Linux CVE debrief
A Linux kernel vulnerability allows a host user to access sensitive data through migration ioctls, although guest data remains secure. The issue arises from the __kvm_inject_pfault_token() function not fully initializing the on-stack struct kvm_s390_irq, leading to stale stack values in ext_params and pad. This information can be obtained by a host user using migration ioctls.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-03
Who should care
Linux kernel maintainers, KVM administrators, and security teams responsible for Linux-based virtualization infrastructure should assess exposure and prioritize remediation. This includes verifying Linux kernel versions and KVM configurations, reviewing system migration ioctls restrictions, and applying Linux kernel updates addressing CVE-2026-89921. Additionally, they should perform vulnerability assessments and inventory affected systems for remediation.
Why it matters
CVE-2026-89921 is a Linux kernel vulnerability that allows a host user to access sensitive data through migration ioctls. Although guest data remains secure, Linux kernel maintainers, KVM administrators, and security teams should assess exposure and prioritize remediation. The issue is resolved in the Linux kernel, and four source references provide details on the specific commits that address the issue.
- Host users can access sensitive data through migration ioctls
- Requires verification of Linux kernel versions and KVM configurations
- Remediation involves applying Linux kernel updates
- Exposure assessment is necessary for Linux-based virtualization infrastructure
Technical summary
The __kvm_inject_pfault_token() function in the Linux kernel does not fully initialize the on-stack struct kvm_s390_irq, leading to sensitive data exposure through migration ioctls. The issue is resolved by zero-initializing the irq struct. This vulnerability allows a host user to access sensitive data, although guest data remains secure. Linux kernel maintainers, KVM administrators, and security teams should assess exposure and prioritize remediation for Linux kernel deployments using KVM on s390 architectures, focusing on verifying system migration ioctls restrictions and applying Linux kernel updates.
Defensive priority
Assess exposure and prioritize remediation for Linux kernel deployments using KVM on s390 architectures.
Recommended defensive actions
- Assess Linux kernel versions and KVM configurations for potential exposure
- Verify system migration ioctls are properly restricted
- Review and apply Linux kernel updates addressing CVE-2026-89921
- Monitor system logs for suspicious migration ioctl activity
- Perform vulnerability assessment for Linux-based virtualization infrastructure
- Inventory and track affected systems for remediation prioritization
- Review compensating controls for exposed systems while remediation is scheduled
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, which is resolved in the Linux kernel. Four source references are provided, detailing the specific commits that address the issue. To verify, defenders should review Linux kernel versions and KVM configurations for potential exposure, and assess the migration ioctls restrictions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89921 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89921
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89921 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89921
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/134f235e0e8de54611a72d3cc3f63e5f31246baa
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4e2c7f7cbc27418f9a290399b986c1b85ff93b90
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9b046de62b8098af6e2ba820b125ec9dc5f162c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b8abc760fa18a389319d977834a30550b3ec18e8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.