CVE EVIDENCE REVIEW
ReviewHighEvidence review

CVE-2026-80550 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Fix out of bounds check on CCW array The routine ccwchain_calc_length() counts the number of channel command words (CCWs) that are chained together in a single channel program, and rejects anything larger than CCWCHAIN_LEN_MAX (256) CCWs. The loop itself is "do..while (count < 257)", and while the logic in is_cpa_within_range() correctly adjusts between the 0-index array of CCWs and the count of CCWs starting at 1, this means it would look at a possible 257th CCW before ending the loop and (correctly) returni...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 0282fb1c4b638eecfe2cc558092c460911d8f7e2, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 907adc667d902fafbdb2d740d57b55bd025dc4cd, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < af3f80ca4c8b17f20f9e588def076288fdb49e65, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 499a8a66b1598bfab97182aed15e0f1646074a3d, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 4c2e1d359d7a2b82cdf3254e4e480af9417f99fb, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < d5d096cd9369e986d4e5153baa86b8b35c283e09, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < a005b7f1a491ffda61bff0fd0f6548f8986fb977, >= 4.12
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 7.9 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 0282fb1c4b638eecfe2cc558092c460911d8f7e2, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 907adc667d902fafbdb2d740d57b55bd025dc4cd, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < af3f80ca4c8b17f20f9e588def076288fdb49e65, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 499a8a66b1598bfab97182aed15e0f1646074a3d, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < 4c2e1d359d7a2b82cdf3254e4e480af9417f99fb, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < d5d096cd9369e986d4e5153baa86b8b35c283e09, >= 0a19e61e6d4c6192077ead760ba0a2d350987d4c < a005b7f1a491ffda61bff0fd0f6548f8986fb977, >= 4.12. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.