CVE-2026-31568: s390/mm: Add missing secure storage access fixups for donated memory

Published Apr 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

s390/mm: Add missing secure storage access fixups for donated memory

There are special cases where secure storage access exceptions happen in a kernel context for pages that don't have the PGarch1 bit set. That bit is set for non-exported guest secure storage (memory) but is absent on storage donated to the Ultravisor since the kernel isn't allowed to export donated pages.

Prior to this patch we would try to export the page by calling archmakefolioaccessible() which would instantly return since the arch bit is absent signifying that the page was already exported and no further action is necessary. This leads to secure storage access exception loops which can never be resolved.

With this patch we unconditionally try to export and if that fails we fixup.

Affected Software

11 affected components
Linux Linux kernel
Linux Linux kernel>=5.7.1<6.18.21
Linux Linux kernel>=6.19<6.19.11
Linux Linux kernel=5.7
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Event History

Apr 24, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 26, 2026
Data Sourced
via Microsoft·08:06 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-31568?

CVE-2026-31568 is classified as a moderate severity vulnerability due to the potential for secure storage access issues.

2

How do I fix CVE-2026-31568?

To fix CVE-2026-31568, users should update their Linux kernel to the latest patched version that addresses the missing secure storage access fixups.

3

Who is affected by CVE-2026-31568?

CVE-2026-31568 affects all installations of the Linux kernel where there is donated memory involved.

4

What kind of systems are vulnerable to CVE-2026-31568?

Systems running the Linux kernel, particularly those using s390 architecture, may be vulnerable to CVE-2026-31568.

5

What are the potential risks of CVE-2026-31568?

The potential risks of CVE-2026-31568 include unauthorized access to secure storage data, which could compromise system integrity and confidentiality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203