Linux Kernel Identity Domain Memory Corruption Vulnerability in IOMMU S390

Vulnerability

A memory corruption vulnerability has been identified in the Linux kernel's IOMMU S390 implementation, specifically when using the identity domain. The issue arises because the identity domain is not associated with a valid S390 domain, leading to a global-out-of-bounds error. This vulnerability was discovered using KASAN, which reported the memory access issue when a device was managed through the identity domain.

Impact

Exploitation of this vulnerability causes memory corruption, with the potential for leading to arbitrary code execution or other memory-related vulnerabilities.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Oct 4, 2025, 8:35 AM
Updated: Oct 4, 2025, 8:35 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
1.3
exploitability
4.0
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.