---
id: CVE-2026-89922
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KVM: s390: Take srcu when importing watchpoint data

  __import_wp_info() backs up the original guest memory contents of a
  watchpoint with read_guest_abs(), which is kvm_…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KVM: s390: Take srcu when importing watchpoint data

  __import_wp_info() backs up the original guest memory contents of a
  watchpoint with read_guest_abs(), which is kvm_…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    6830fbc3724bf49c142aae69a4694f115fa9cedd
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    f8e3a9997d5ecd56ebe4b262ff424516c068fecb
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    cc710ee45395efb4937e042960f791d33924e5f6
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    4c05bf21d1806853e662cc19e744736a3408f155
  - >-
    Linux >= 27291e2165b6de70c476b7b675308113edd69a60 <
    a4e482def8533ebace517d9f67f1465841b1f982
  - Linux 3.16
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:18.357'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89922'
references:
  - url: 'https://git.kernel.org/stable/c/4c05bf21d1806853e662cc19e744736a3408f155'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6830fbc3724bf49c142aae69a4694f115fa9cedd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/76f5b4ea9ed0aa5a34bda9d8a878f2c73026ec03'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a4e482def8533ebace517d9f67f1465841b1f982'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc710ee45395efb4937e042960f791d33924e5f6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f8e3a9997d5ecd56ebe4b262ff424516c068fecb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.972Z'
epss: 0.00164
epssPercentile: 0.06031
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Take srcu when importing watchpoint data

__import_wp_info() backs up the original guest memory contents of a
watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore
resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or
kvm->slots_lock) to be held, otherwise a concurrent memslot update can
free the memslots array under us once its SRCU grace period has elapsed.

As this is not fast path, following lock ordering (mutex first, then
srcu) take the big hammer and hold the srcu for the full import.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
