PatchSiren cyber security CVE debrief
CVE-2026-97589 Linux CVE debrief
A vulnerability in the Linux kernel's s390/crypto implementation can cause a double completion of cryptographic requests, potentially leading to undefined behavior. The issue arises when the do_one_request callback returns a negative error code instead of 0 after explicit finalization of a request. This has been fixed in the affected callbacks. The vulnerability affects Linux kernel systems utilizing s390/crypto functionalities. Defenders and administrators should assess exposure and prioritize patching to mitigate potential risks. The CVE record and NVD entry provide details on the vulnerability, including its description and affected components.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders and administrators responsible for Linux kernel systems, especially those utilizing s390/crypto functionalities, should assess exposure and prioritize patching to mitigate potential risks.
Why it matters
CVE-2026-97589 is a vulnerability in the Linux kernel's s390/crypto implementation that can cause a double completion of cryptographic requests. Defenders should prioritize verifying and applying patches, reviewing system configurations, and monitoring system logs to mitigate potential risks.
- Verification of patch application is required to prevent potential double completion of cryptographic requests
- Monitoring system logs for indicators of exploitation or undefined behavior is necessary
- Reviewing system configurations and cryptographic request handling is recommended
Technical summary
The Linux kernel's s390/crypto implementation has a vulnerability that can cause a double completion of cryptographic requests. This occurs when the do_one_request callback returns a negative error code instead of 0 after explicit finalization of a request, potentially leading to undefined behavior. Fixes have been applied to the affected callbacks in paes_s390.c and phmac_s390.c. The vulnerability affects Linux kernel systems utilizing s390/crypto functionalities. Defenders should prioritize verifying and applying patches for Linux kernel versions impacted by this vulnerability, particularly in environments utilizing s390/crypto functionalities. The CVE record and NVD entry provide details on the vulnerability
Defensive priority
Defenders should prioritize verifying and applying patches for Linux kernel versions impacted by this vulnerability, particularly in environments utilizing s390/crypto functionalities.
Recommended defensive actions
- Verify and apply patches for Linux kernel versions impacted by this vulnerability
- Review system configurations and cryptographic request handling
- Monitor system logs for potential indicators of exploitation
- Perform a thorough review of the system's cryptographic request handling to identify potential vulnerabilities
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and affected components. However, specific version ranges and potentially affected systems require further verification from official Linux kernel sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97589 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97589
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97589 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97589
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5480291aa848e19e61175abfd457933516db70c6
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/972e0d9b7d1d112240ccde1f1be85bf9ffaa1720
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ac1481320110b803ab9b79ab4d2ca11a74fc05f2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.