---
id: CVE-2026-80921
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KVM: s390: vsie: zero stale crypto bits

  When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
  the bits 64..255 are unchanged from whatever is in the vs…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KVM: s390: vsie: zero stale crypto bits

  When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
  the bits 64..255 are unchanged from whatever is in the vs…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    d110b3297f11ef227098b8a82ade2d5f123b7d2f
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    59d51550b5cb916bda037673a721a404b3b47a0d
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    f6079dca67eccb5eabef9f72437948c66dc5131f
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    087c19cc60a8caa1a08e1e434c8be2caf6c27733
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    7d23489f51109e3ebba5b5db8c5f0185af7b7fdf
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    935eeba276012916c76243e5cbb843efd8fdb75d
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    d4bcd2df6d0d2af916b4fe1a533958778ea7c45b
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6
  - >-
    Linux >= 6b79de4b056e5a2febc0c61233d8f0ad7868e49c <
    34d5b5b646c91cfb9338d7a12c955a70ffb8c66b
  - Linux 4.20
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T06:17:06.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80921'
references:
  - url: 'https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/935eeba276012916c76243e5cbb843efd8fdb75d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d110b3297f11ef227098b8a82ade2d5f123b7d2f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d4bcd2df6d0d2af916b4fe1a533958778ea7c45b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f6079dca67eccb5eabef9f72437948c66dc5131f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-09T17:16:03.090Z'
epss: 0.00184
epssPercentile: 0.07007
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: vsie: zero stale crypto bits

When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested guest potential access
to a device no longer available. Zero out the remaining bits.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
