In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: pv: fix index value of replaced ASCE
The index field of the struct page corresponding to a guest ASCE should be 0. When replacing the ASCE in s390_replace_asce(), the index of the new ASCE should also be set to 0.
Having the wrong index might lead to the wrong addresses being passed around when notifying pte invalidations, and eventually to validity intercepts (VM crash) if the prefix gets unmapped and the notifier gets called with the wrong address.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 29, 2025 | Dec 29, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 24, 2025 |
| Ubuntu | — | Upgrade linux-lowlatencyUpgrade linux-ibmUpgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-realtimeUpgrade linux-bluefieldUpgrade linux-nvidiaUpgrade linux-hwe-5.15Upgrade linux-azureUpgrade linux-azure-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-raspiUpgrade linux-oracle-5.15Upgrade linux-kvmUpgrade linux-gkeopUpgrade linux-intel-iotgUpgrade linux-xilinx-zynqmpUpgrade linux-oracleUpgrade linux-nvidia-tegra-5.15Upgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-nvidia-tegraUpgrade linux-ibm-5.15Upgrade linux-awsUpgrade linux-gkeUpgrade linux-intel-iot-realtimeUpgrade linux-riscv-5.15Upgrade linuxUpgrade linux-nvidia-tegra-igx | Jan 6, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub