PatchDayAlert

CVE

CVE-2026-68454

0field notes · 1digest CVSS 8.8

The verdict

A KVM bug on s390 (IBM Z) lets a guest VM register PCI interrupts without a summary bit, causing the host kernel to store a bogus physical address derived from NULL. This can corrupt host memory or crash the hypervisor. Exploitation requires a malicious or compromised guest running on s390 KVM, so this only matters if you run KVM on IBM Z hardware.

Patch urgency · Patch this week


Daily digests