CVE-2026-80684: Linux
Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure The airq_iv_create() can return NULL on failure, but the return value was never checked. If it fails, zdev->aibv will be NULL and fail when dereferenced in kvm_zpci_set_airq(). Add a NULL check and free the previously allocated AISB bit and zdev->aisb on failure.
Affected products
- Linux Linux: from 6.0, before 6.1.183 (fixed in 6.1.183); from 6.2, before 6.6.151 (fixed in 6.6.151); from 6.7, before 6.12.103 (fixed in 6.12.103); from 6.13, before 6.18.44 (fixed in 6.18.44); from 6.19, before 7.1.8 (fixed in 7.1.8)
Published 2026-08-28. Last modified 2026-08-29.