Executive brief
A vulnerability was identified in the Linux kernel's s390 architecture support for Adjunct Processor (AP) devices, which are used for cryptographic operations. A race condition in how the system handles driver overrides could allow a local attacker to cause a system crash or unpredictable behavior. This issue primarily affects the stability and availability of systems using s390 cryptographic hardware.
Technical details
A use-after-free (UAF) vulnerability exists in the s390 AP bus implementation within the Linux kernel. When AP masks are updated via apmask_store() or aqmask_store(), the function ap_bus_revise_bindings() calls __ap_revise_reserved() after the ap_attr_mutex has been released. This creates a race condition where __ap_revise_reserved() accesses the driver_override field without proper locking while a concurrent driver_override_store() operation may free the underlying string. An attacker with local access to sysfs attributes could exploit this race to cause a kernel panic or memory corruption. The fix migrates the AP bus to the generic driver-core driver_override infrastructure, which utilizes internal spinlocks to protect these accesses.
Affected products
- Linux Linux Kernel 6.19, 7.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory