Junglewise Threat Intelligence

CVE-2025-71155: Linux Kernel KVM memory corruption in gmap_helper_zap_one_page

CVE-2025-71155 · Severity: high · CVSS 7.8 · Published 2026-01-23

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component for IBM Z (s390x) systems could allow a local user to cause memory corruption within a guest virtual machine. This issue affects environments using KVM (Kernel-based Virtual Machine) and could lead to system instability or unauthorized access to data within the guest environment. Patches have been released to address the missing safety checks in the memory management code.

Technical details

An out-of-bounds write (CWE-787) vulnerability exists in the Linux kernel's s390 KVM implementation. The root cause is missing validation checks in gmap_helper_zap_one_page() within arch/s390/mm/gmap_helpers.c when handling swapped pages. Specifically, the function failed to verify the PGSTE (Page Status Table Entry) usage mask and zero flags before zapping and clearing a Page Table Entry (PTE). A local attacker with low privileges could exploit this to cause memory corruption in a guest virtual machine. The issue has been resolved by adding the necessary checks to ensure the page is marked as unused or zero before proceeding with the zap operation.

Affected products

  • Linux Linux Kernel 6.17.4 to 6.18.4

Timeline

  • 2025-11-04: other: Initial fix commit authored
  • 2026-01-23: disclosed: CVE published
  • 2026-01-08: patched: Fix committed to stable tree

References

Related threats