Answer in brief
CVE-2026-89924 records a Unknown severity vulnerability in KVM: s390: Fix old_data leak in guest debug error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=27291e2165b6de70c476b7b675308113edd69a60 <124c81ee610e1fbdd93d4399f88d9e28ba97a941 || >=27291e2165b6de70c476b7b675308113edd69a60 <e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4 || >=27291e2165b6de70c476b7b675308113edd69a60 <c85d402553987777cc4742751437ea5dcbf98a7b || >=27291e2165b6de70c476b7b675308113edd69a60 <5fbf319137735252eefa507193c9a619af5b7457 || >=27291e2165b6de70c476b7b675308113edd69a60 <4048d0a252163084794be3e37995b872c5178913 || >=27291e2165b6de70c476b7b675308113edd69a60 <f55e4d415d95342d5753e528e05a1e8623992c3f || >=27291e2165b6de70c476b7b675308113edd69a60 <46cb8a273e2f853f89a78b59dbdff8787b6e1c86 || >=27291e2165b6de70c476b7b675308113edd69a60 <aa9c8e8baf1e765fa65b93212522c636f25d846f | 124c81ee610e1fbdd93d4399f88d9e28ba97a941, e5ae7816e5ad145618f7fd568a0e8a94dd9f81f4, c85d402553987777cc4742751437ea5dcbf98a7b, 5fbf319137735252eefa507193c9a619af5b7457, 4048d0a252163084794be3e37995b872c5178913, f55e4d415d95342d5753e528e05a1e8623992c3f, 46cb8a273e2f853f89a78b59dbdff8787b6e1c86, aa9c8e8baf1e765fa65b93212522c636f25d846f |
| Linux/Linuxgeneric | 3.16 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix old_data leak in guest debug error path __import_wp_info() allocates a per-watchpoint old_data buffer to back up the original guest memory contents. If a later watchpoint of the same KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data() jumps to the error label, which frees the wp_info array but not the old_data buffers of the entries that were imported successfully. Up to MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed request, and the request can be repeated. Create error handling for cleaning up all created old_data memory areas.
Quoted source text, attributed separately from HOL analysis.