VDB

CVE-2026-80921

CVE-2026-80921 PUBLISHED CVSS 8.8 HIGH

Reported by Linux · Published September 9, 2026

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.

EPSS 0.13% · 2.6th percentile

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.13%
2.6th percentile

Affected Products

VendorProductVersions
LinuxLinux6b79de4b056e5a2febc0c61233d8f0ad7868e49c, 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, 6b79de4b056e5a2febc0c61233d8f0ad7868e49c
LinuxLinux4.20, 0, 5.10.269
linuxlinux_kernel4.20, 4.20, 4.20
LinuxLinux6b79de4b056e5a2febc0c61233d8f0ad7868e49c, 6b79de4b056e5a2febc0c61233d8f0ad7868e49c, 6b79de4b056e5a2febc0c61233d8f0ad7868e49c

Timeline

  • Sep 9, 2026 Coalition ESS Score
  • Sep 9, 2026 CVE Published
  • Sep 10, 2026 EPSS Score
  • Sep 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›