Executive brief
A vulnerability in the Linux kernel for s390 architecture systems could allow certain programming errors to go undetected, potentially leading to system instability or unauthorized data access. Specifically, the system fails to properly block access to memory address zero, which is normally reserved to catch software bugs. This could allow a local attacker to exploit kernel memory management flaws that would otherwise be stopped by standard security protections.
Technical details
A vulnerability exists in the s390 memory management (mm) subsystem of the Linux kernel where the 'lowcore' (the first two pages of physical memory) is incorrectly included in the identity mapping. Because the identity mapping is pinned to address zero, NULL pointer accesses may succeed rather than causing a processor exception, bypassing standard NULL pointer dereference protections. While s390 'low address protection' provides partial coverage, it does not fully mitigate the risk of an attacker leveraging a NULL pointer dereference to achieve arbitrary code execution or data leakage. The fix involves modifying arch/s390/boot/vmem.c to ensure the first two pages of physical memory are never included in the identity mapping. Patches are available in stable kernel releases 6.12.44, 6.16.4, and 6.17.
Affected products
- Linux Linux Kernel 6.10.11 to 6.11, 6.11.1 to 6.12.44, 6.13 to 6.16.4
Timeline
- 2025-08-07: patched: Initial patch authored by Heiko Carstens
- 2025-09-05: disclosed: CVE published