← All Advisories

Linux kernel s390/mm missing secure storage access fixups for donated pages causes kernel context exceptions

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-31568

Key Details

CVECVE-2026-31568
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is high.
Affected productsLinux Linux Kernel
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsGeneral OT
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

s390/mm: Add missing secure storage access fixups for donated memory

There are special cases where secure storage access exceptions happen

in a kernel context for pages that don't have the PG_arch_1 bit

set. That bit is set for non-exported guest secure storage (memory)

but is absent on storage donated to the Ultravisor since the kernel

isn't allowed to export donated pages.

Prior to this patch we would try to export the page by calling

arch_make_folio_accessible() which would instantly return since the

arch bit is absent signifying that the page was already exported and

no further action is necessary. This leads to secure storage access

exception loops which can never be resolved.

With this patch we unconditionally try to export and if that fails we

fixup. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31568
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31568