Executive brief
A vulnerability in the Linux kernel's s390x Internal Shared Memory (ISM) driver can cause network connections to fail or the device to enter an unrecoverable error state. This occurs because the driver fails to properly manage simultaneous requests to the hardware, which can lead to data corruption or command errors. In practice, this could result in a total loss of connectivity for services relying on these specialized IBM Z network functions and potentially allow for broader system instability.
Technical details
A race condition exists in the s390/ism driver within the ism_cmd() function. The s390x ISM device architecture requires a strict one-at-a-time request-response sequence per ISM function; however, the driver lacked sufficient locking to enforce this. Under concurrent workloads, multiple CPUs could attempt to issue commands simultaneously, leading to firmware inputs being partially overwritten or corrupted. This results in PCI error events (such as PEC 2 or PEC 3A), invalid DMA operations, and the device entering a dysfunctional state that requires a manual reset as the driver lacks auto-recovery support. The fix introduces a spinlock (cmd_lock) to serialize command execution.
Affected products
- Linux Linux 4.19 to 6.6.101, 6.12.41, 6.15.9
Timeline
- 2025-07-22: patched: Initial patch authored by IBM engineers.
- 2025-09-05: disclosed: CVE-2025-39726 published.