s390/vfio_ccw: Ensure first IDAW remains constant
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Ensure first IDAW remains constant
The first IDAW in a list does not need to be on a 2K/4K boundary
like all others, and so is read separately to accurately calculate
the size of the buffer needed to read the full IDAL.
Verify that the address found in the first IDAW is unchanged between
reads, to ensure a consistent set of IDAWs being worked with.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/08ef2a82115690d6e229615872ac1731af732497https://git.kernel.org/stable/c/0d46c2565f173bcddcdcaf44a4f69789a20535e2https://git.kernel.org/stable/c/460b977a4e71cc319fdadf91c193ec3beaa57263https://git.kernel.org/stable/c/565bef268d75bf7df665bce6923a88cd0eb74592https://git.kernel.org/stable/c/fc59e9482117ebdccd6dc7fa8082f8b980fd021e