Answer in brief
CVE-2026-89926 records a Unknown severity vulnerability in KVM: s390: Fix length check __import_wp_info(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=27291e2165b6de70c476b7b675308113edd69a60 <aef540194effd768bed0bd2e6a74fe135a3d7c3a || >=27291e2165b6de70c476b7b675308113edd69a60 <71153d3262517e1c02c3a66aa5094f279b2d1454 || >=27291e2165b6de70c476b7b675308113edd69a60 <fec89d327d9b2b669b5bbdac209386c6317c3722 || >=27291e2165b6de70c476b7b675308113edd69a60 <b94ab9caa5d72c78226121cccff5e33f946da900 || >=27291e2165b6de70c476b7b675308113edd69a60 <beb9c55af609c4c7308259d7191688c75a4e3d4a || >=27291e2165b6de70c476b7b675308113edd69a60 <3fe801db90bdeefb0bbdda42d832846b53f64f8a || >=27291e2165b6de70c476b7b675308113edd69a60 <4c07680a467e2f7697245bcd11691bffb2a6f0ed | aef540194effd768bed0bd2e6a74fe135a3d7c3a, 71153d3262517e1c02c3a66aa5094f279b2d1454, fec89d327d9b2b669b5bbdac209386c6317c3722, b94ab9caa5d72c78226121cccff5e33f946da900, beb9c55af609c4c7308259d7191688c75a4e3d4a, 3fe801db90bdeefb0bbdda42d832846b53f64f8a, 4c07680a467e2f7697245bcd11691bffb2a6f0ed |
| Linux/Linuxgeneric | 3.16 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix length check __import_wp_info() struct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user space. This is then assigned to wp_info->len, which is an int. The bounds check is done on the truncated value while the allocation uses the untruncated one: wp_info->len = bp_data->len; [...] if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE) return -EINVAL; wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT); Use the validated value for the allocation as intended. Without this fix userspace can trigger >4GB allocations which will fail and result in a WARN due to MAX_PAGE_ORDER.
Quoted source text, attributed separately from HOL analysis.