In the Linux kernel, the following vulnerability has been resolved:
KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler
We do check for target CPU == -1, but this might change at the time we are going to use it. Hold the physical target CPU in a local variable to avoid out-of-bound accesses to the cpu arrays.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Sep 17, 2025 | Sep 17, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Sep 15, 2025 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-gkeUpgrade linux-lowlatencyUpgrade linux-intel-iot-realtimeUpgrade linux-nvidia-tegraUpgrade linux-bluefieldUpgrade linux-riscv-5.15Upgrade linux-ibm-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.15Upgrade linux-nvidia-tegra-5.15Upgrade linux-raspiUpgrade linux-awsUpgrade linuxUpgrade linux-intel-iotgUpgrade linux-azure-5.15Upgrade linux-hwe-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-oracleUpgrade linux-gcp-5.15Upgrade linux-oracle-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-ibmUpgrade linux-gkeopUpgrade linux-xilinx-zynqmpUpgrade linux-kvmUpgrade linux-realtimeUpgrade linux-azureUpgrade linux-nvidia | Sep 19, 2025 | Sep 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub