Bug 2516230 (CVE-2026-72292)
| Summary: | CVE-2026-72292 kernel: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the kernel. A local user could exploit a vulnerability in the KVM_S390_GET_CMMA_BITS ioctl, specifically within the `kvm_s390_get_cmma_bits()` function. This function allocates memory without properly initializing all pages, leading to uninitialized memory regions. These uninitialized regions can then be copied to user space, resulting in the disclosure of stale kernel memory.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-15 06:01:40 UTC
|