8.8
HIGH CVSS 3.1
CVE-2026-80921
KVM: s390: vsie: zero stale crypto bits
Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.

INFO

Published Date :

Sept. 9, 2026, 5:17 p.m.

Last Modified :

Sept. 10, 2026, 6:17 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-80921 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Zero out stale crypto bits in KVM s390 to prevent unauthorized device access.
  • Apply the provided kernel patch.
  • Update to a patched Linux kernel version.
  • Ensure crypto access bits are properly zeroed.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-80921 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-80921 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-80921 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-80921 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 10, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 09, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/80xxx/CVE-2026-80921.json">CVE-2026-80921</a>
    Added Reference https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733
    Added Reference https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6
    Added Reference https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b
    Added Reference https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d
    Added Reference https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf
    Added Reference https://git.kernel.org/stable/c/935eeba276012916c76243e5cbb843efd8fdb75d
    Added Reference https://git.kernel.org/stable/c/d110b3297f11ef227098b8a82ade2d5f123b7d2f
    Added Reference https://git.kernel.org/stable/c/d4bcd2df6d0d2af916b4fe1a533958778ea7c45b
    Added Reference https://git.kernel.org/stable/c/f6079dca67eccb5eabef9f72437948c66dc5131f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.