Executive brief
A vulnerability exists in the Linux kernel's s390 architecture support, specifically within the Service Call Control Block (SCCB) handling. In certain configurations where memory mapping does not start at address zero, the system may fail to properly identify empty data structures during hardware interrupts. This can lead to incorrect memory access, potentially resulting in system instability, data exposure, or unauthorized modifications to kernel memory.
Technical details
A vulnerability in the s390 SCLP (Service Element Communications Protocol) driver arises from an improper NULL check in the interrupt handler's tracing code. The code performs a NULL check on the SCCB address only after physical-to-virtual address translation (__va). If the kernel identity mapping starts at a non-zero offset, the translated virtual address will never be NULL even if the physical address is zero, causing the check to fail. This leads to a NULL pointer dereference or incorrect access to the first page of the identity mapping. The fix introduces a helper function to validate the SCCB address before translation occurs. Patches are available in various stable kernel branches including 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.16 to 6.1.149, 6.6.103, 6.12.44, 6.16.4
- Siemens SIMATIC CN 4100 before V5.0
Timeline
- 2025-08-18: patched: Initial patch authored by Peter Oberparleiter
- 2025-09-05: disclosed: CVE published
References
- https://git.kernel.org/stable/c/430fa71027b6ac9bb0ce5532b8d0676777d4219a
- https://git.kernel.org/stable/c/61605c847599fbfdfafe638607841c7d73719081
- https://git.kernel.org/stable/c/86c2825791c3836a8f77a954b9c5ebe6fab410c5
- https://git.kernel.org/stable/c/aa5073ac1a2a274812f3b04c278992e68ff67cc7
- https://git.kernel.org/stable/c/bf83ae3537359af088d6577812ed93113dfbcb7b
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html