CVE-2026-80548: s390/vfio_ccw: Selectively expand io_mutex
In the Linux kernel, the following vulnerability has been resolved:
s390/vfioccw: Selectively expand iomutex
The iomutex was defined to serialize the ioregions, but then has also sort of been associated with the I/O themselves because of the close relationship they share.
With the handful of races that are possible, the choices are either to: A) expand the scope of iomutex to close these remaining windows, or B) reduce the scope of iomutex to just ioregion, and introduce a new lock mechanism for the remaining I/O resources
This patch implements A, since B brings with it a lot more interactions that would need to be tracked and kept in a correct hierarchy. It also takes advantage of the workqueue element for cpfree() that now gets called out of fsmnotoper(), which could be invoked out of an interrupt context and thus cannot acquire a mutex itself.
Affected Software
Event History
Frequently Asked Questions
Does the fix introduce a separate lock for I/O resources?
No. The selected approach expands the scope of the existing io_mutex to close remaining race windows rather than adding a new locking mechanism and hierarchy.
How does the fix handle cleanup that may originate in interrupt context?
It uses a workqueue element for cp_free(), allowing it to run outside fsm_notoper(), which may be invoked from interrupt context and therefore cannot acquire a mutex.