Answer in brief
CVE-2026-80921 records a Unknown severity vulnerability in KVM: s390: vsie: zero stale crypto bits. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <d110b3297f11ef227098b8a82ade2d5f123b7d2f || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <59d51550b5cb916bda037673a721a404b3b47a0d || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <f6079dca67eccb5eabef9f72437948c66dc5131f || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <087c19cc60a8caa1a08e1e434c8be2caf6c27733 || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <7d23489f51109e3ebba5b5db8c5f0185af7b7fdf || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <935eeba276012916c76243e5cbb843efd8fdb75d || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <d4bcd2df6d0d2af916b4fe1a533958778ea7c45b || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6 || >=6b79de4b056e5a2febc0c61233d8f0ad7868e49c <34d5b5b646c91cfb9338d7a12c955a70ffb8c66b | d110b3297f11ef227098b8a82ade2d5f123b7d2f, 59d51550b5cb916bda037673a721a404b3b47a0d, f6079dca67eccb5eabef9f72437948c66dc5131f, 087c19cc60a8caa1a08e1e434c8be2caf6c27733, 7d23489f51109e3ebba5b5db8c5f0185af7b7fdf, 935eeba276012916c76243e5cbb843efd8fdb75d, d4bcd2df6d0d2af916b4fe1a533958778ea7c45b, 29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6, 34d5b5b646c91cfb9338d7a12c955a70ffb8c66b |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Sep 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 9, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
Quoted source text, attributed separately from HOL analysis.