CVE-2026-68454
KVM s390 kernel bug may leak host physical address / crash VMs during guest IRQ registration.
Is CVE-2026-68454 being exploited?
Not confirmed. CVE-2026-68454 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-68454?
CVE-2026-68454 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-68454?
Yes. A fix has been recorded for CVE-2026-68454. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-68454 affect?
CVE-2026-68454 affects Linux kernel (KVM) on s390 / IBM Z. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-68454?
Update Linux kernel/KVM on s390 to vendor-fixed release immediately.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A crafted guest PCI/IRQ registration can cause incorrect physical address handling, enabling host memory disclosure, guest crash, or possible VM escape.
Patch when possible
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < f887df91826e72b570c5e9298e66dd929f09edde
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < 3ef3190e30601b2688bdc64169b938b8d7f42010
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < d48b9b096d11e31690c0a4988f65f21b64c01b2a
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < df72596278b0e22dac5ef2881e9221a3a2c4ed11
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < 124a3769c43713a11a93a821b313e61ad5110cb8
- affected>= 3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc and < 3e3aa6da87d30a0064a17b836685cd43c90a3572
- affected6.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.