Review reviewHigh

CVE-2026-52968

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() index the GAIT by manually multiplying the index with sizeof(struct zpci_gaite). Since aift->gait is already a struct zpci_gaite pointer, this double-scales the offset, accessing element aisb*16 instead of aisb. This causes out-of-bounds accesses when aisb >= 32 (with ZPCI_NR_DEVICES=512) Fix by removing the erroneous sizeof multiplication.

CVSS
7.1
EPSS
0.14%
3.68% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic kvm_s390_pci_aif_enable(), kvm_s390_pci_aif_disable(), and aen_host_forward() index the GAIT by manually multiplying the index with sizeof(struct zpci_gaite). Since aift->gait is already a struct zpci_gaite pointer, this double-scales the offset, accessing element aisb*16 instead of aisb. This causes out-of-bounds accesses when aisb >= 32 (with ZPCI_NR_DEVICES=512) Fix by removing the erroneous sizeof multiplication.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 73f91b004321f2510fa79e66035dbbf1870fcf56 < 31a9d9f9942885aae356a1a57c79e82c5b5b0828, >= 73f91b004321f2510fa79e66035dbbf1870fcf56 < a99a25db131ece5e6c0f7632da606de631efe4f2, >= 73f91b004321f2510fa79e66035dbbf1870fcf56 < 11b8ff5b930b351dd1f6f088dce0beb027ac92d0, >= 73f91b004321f2510fa79e66035dbbf1870fcf56 < b22a2da8792a7bfe743c1a922e77fa499ddedbe8, >= 73f91b004321f2510fa79e66035dbbf1870fcf56 < e7216651b94e92e5433fb2f54b77864642b4ea48, >= 73f91b004321f2510fa79e66035dbbf1870fcf56 < 16d990a15491cf76cd6eef0846e1b4100e63261a, >= 6.0, >= 6.0 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10, 7.1
Fixed versions
6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125