Answer in brief
CVE-2026-89957 records a Unknown severity vulnerability in s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <f58e824de8577fe411f6199d659731a0f86a7275 || >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <3a9b049bbdc40165d7f3e20b818eec95e5694d96 || >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <753aa3bb1273bc0d36adb013d5915cc8ff6b72a9 || >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <c45753c32d452d10d8efaeb52587e9e6e8126e33 || >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <04b35dd88c108b2d2ceaaa396aba1cb4049d5831 || >=eeb386aeb5b7c8d2dae6a3ba49255d8a97803182 <917f509bfb88048094dbb85c4e9dbc4d6fe4a886 | f58e824de8577fe411f6199d659731a0f86a7275, 3a9b049bbdc40165d7f3e20b818eec95e5694d96, 753aa3bb1273bc0d36adb013d5915cc8ff6b72a9, c45753c32d452d10d8efaeb52587e9e6e8126e33, 04b35dd88c108b2d2ceaaa396aba1cb4049d5831, 917f509bfb88048094dbb85c4e9dbc4d6fe4a886 |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of bitmap_andnot() to determine whether the guest APCB needs to be updated. However, bitmap_andnot() returns false when the resulting destination bitmap is empty. This means that if the only adapter, domain or control domain assigned to an mdev is removed from the host's AP configuration, the bit is correctly cleared from the shadow APCB, but bitmap_andnot() returns false because the result is an empty bitmap. Consequently, do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called, leaving the KVM guest with stale hardware access to the unplugged AP devices. Fix this by replacing the bitmap_andnot() return value check with bitmap_intersects() to determine whether the shadow APCB actually overlaps with the removal mask. If there is an intersection, call bitmap_andnot() solely for its side effect of clearing the bits, then unconditionally set do_hotplug to trigger the guest APCB update.
Quoted source text, attributed separately from HOL analysis.