0.0
NA
CVE-2026-89924
KVM: s390: Fix old_data leak in guest debug error path
Description

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas.

INFO

Published Date :

Sept. 16, 2026, 11:17 a.m.

Last Modified :

Sept. 16, 2026, 11:17 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-89924 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Ensure proper cleanup of allocated memory buffers in KVM guest debug error paths.
  • Apply kernel patches to fix memory leaks.
  • Review error handling for resource management.
  • Test error paths for data leaks.
  • Update kernel to the latest secure version.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-89924 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-89924 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-89924 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-89924 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 16, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/89xxx/CVE-2026-89924.json">CVE-2026-89924</a>
    Added Reference https://git.kernel.org/stable/c/124c81ee610e1fbdd93d4399f88d9e28ba97a941
    Added Reference https://git.kernel.org/stable/c/4048d0a252163084794be3e37995b872c5178913
    Added Reference https://git.kernel.org/stable/c/46cb8a273e2f853f89a78b59dbdff8787b6e1c86
    Added Reference https://git.kernel.org/stable/c/5fbf319137735252eefa507193c9a619af5b7457
    Added Reference https://git.kernel.org/stable/c/aa9c8e8baf1e765fa65b93212522c636f25d846f
    Added Reference https://git.kernel.org/stable/c/c85d402553987777cc4742751437ea5dcbf98a7b
    Added Reference https://git.kernel.org/stable/c/e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4
    Added Reference https://git.kernel.org/stable/c/f55e4d415d95342d5753e528e05a1e8623992c3f
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.