Answer in brief
CVE-2026-52968 records a Unknown severity vulnerability in KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=73f91b004321f2510fa79e66035dbbf1870fcf56 <31a9d9f9942885aae356a1a57c79e82c5b5b0828 || >=73f91b004321f2510fa79e66035dbbf1870fcf56 <a99a25db131ece5e6c0f7632da606de631efe4f2 || >=73f91b004321f2510fa79e66035dbbf1870fcf56 <11b8ff5b930b351dd1f6f088dce0beb027ac92d0 || >=73f91b004321f2510fa79e66035dbbf1870fcf56 <b22a2da8792a7bfe743c1a922e77fa499ddedbe8 || >=73f91b004321f2510fa79e66035dbbf1870fcf56 <e7216651b94e92e5433fb2f54b77864642b4ea48 || >=73f91b004321f2510fa79e66035dbbf1870fcf56 <16d990a15491cf76cd6eef0846e1b4100e63261a | 31a9d9f9942885aae356a1a57c79e82c5b5b0828, a99a25db131ece5e6c0f7632da606de631efe4f2, 11b8ff5b930b351dd1f6f088dce0beb027ac92d0, b22a2da8792a7bfe743c1a922e77fa499ddedbe8, e7216651b94e92e5433fb2f54b77864642b4ea48, 16d990a15491cf76cd6eef0846e1b4100e63261a |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Jun 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 24, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() index the GAIT by manually multiplying the index with sizeof(struct zpci_gaite). Since aift->gait is already a struct zpci_gaite pointer, this double-scales the offset, accessing element aisb*16 instead of aisb. This causes out-of-bounds accesses when aisb >= 32 (with ZPCI_NR_DEVICES=512) Fix by removing the erroneous sizeof multiplication.
Quoted source text, attributed separately from HOL analysis.