KernelScan.io

HIGH Introduced in 4.20

kvm CryptoBits Leak

CVE-2026-80921

CVSS 8.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

KernelScan AI5.2MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.

02

Engine v0.6.0

Risk summary

A nested guest running on an s390x KVM host with nested virtualization enabled can retain access to cryptographic devices that have been revoked or were never assigned, due to stale bits in the shadowed crypto access control block. This allows unauthorized use of host crypto hardware by the nested guest. The issue affects any s390x KVM deployment using nested virtualization (vsie) with format-0 crypto control blocks.

Affectedarch/s390/kvm/vsie.c (KVM s390 vsie)

Vulnerability analysis

When an s390x KVM host sets up crypto access controls for a nested guest using a smaller-format crypto control block, it only properly filters the lower bits of each access bitmap, leaving the remaining bits with stale values from the shadow page. These stale bits can grant the nested guest access to cryptographic devices that should no longer be available to it. The fix zeroes the entire shadow control block before copying in only the valid bits, so no stale permissions persist. The vulnerability is reachable from a nested guest on an s390x KVM host with nested virtualization enabled, and the impact is unauthorized access to host cryptographic devices.

03

BranchIntroducedFixed inPatch commit
5.104.205.10.269d110b3297f11
5.154.205.15.22059d51550b5cb
6.14.206.1.187f6079dca67ec
6.124.206.12.1087d23489f5110
6.184.206.18.49935eeba27601
6.64.206.6.156087c19cc60a8
7.14.207.1.13d4bcd2df6d0d
7.24.207.2.329b4f7bc2991
mainline4.207.3-rc134d5b5b646c9