CVE-2026-31568: s390/mm: Add missing secure storage access fixups for donated memory
In the Linux kernel, the following vulnerability has been resolved:
s390/mm: Add missing secure storage access fixups for donated memory
There are special cases where secure storage access exceptions happen in a kernel context for pages that don't have the PGarch1 bit set. That bit is set for non-exported guest secure storage (memory) but is absent on storage donated to the Ultravisor since the kernel isn't allowed to export donated pages.
Prior to this patch we would try to export the page by calling archmakefolioaccessible() which would instantly return since the arch bit is absent signifying that the page was already exported and no further action is necessary. This leads to secure storage access exception loops which can never be resolved.
With this patch we unconditionally try to export and if that fails we fixup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31568?
CVE-2026-31568 is classified as a moderate severity vulnerability due to the potential for secure storage access issues.
How do I fix CVE-2026-31568?
To fix CVE-2026-31568, users should update their Linux kernel to the latest patched version that addresses the missing secure storage access fixups.
Who is affected by CVE-2026-31568?
CVE-2026-31568 affects all installations of the Linux kernel where there is donated memory involved.
What kind of systems are vulnerable to CVE-2026-31568?
Systems running the Linux kernel, particularly those using s390 architecture, may be vulnerable to CVE-2026-31568.
What are the potential risks of CVE-2026-31568?
The potential risks of CVE-2026-31568 include unauthorized access to secure storage data, which could compromise system integrity and confidentiality.