← All Advisories

CVE-2026-97593

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97593

Key Details

CVECVE-2026-97593
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX

When using a 5-level translation table via ZPCI_TABLE_TYPE_RFX

get_rso_from_iova() returns NULL when the region-first entry is invalid.

Yet in get_rto_from_iova() the region-second origin rso is not checked

to be non-NULL before accessing rso[rsx] leading to a NULL pointer

dereference instead of a NULL return when iova_to_phys() is called on

a unmapped IOVA. Fix this by adding the missing NULL check. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97593
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97593