In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data… (CVE-2026-89457)
A vulnerability in the Linux kernel s390/dasd subsystem was resolved that involved sysfs discipline callbacks dereferencing unallocated private data. Specifically, during the dasd_generic_set_online() process, discipline callbacks accessed device->private before it was allocated, causing a NULL pointer dereference and kernel panic. The fix involved guarding these dereferences to prevent accessing uninitialized memory.
AI Analysis
Technical Summary
The Linux kernel s390/dasd subsystem had a vulnerability where several sysfs show/store handlers called discipline callbacks that dereferenced device->private before it was allocated. This occurred because the discipline was assigned prior to check_device() allocating device->private during dasd_generic_set_online(). An unprivileged user could trigger a NULL pointer dereference by reading world-readable sysfs attributes in this timing window, resulting in a kernel panic. The vulnerability was fixed by adding guards around the dereferences inside each affected callback.
Potential Impact
An unprivileged user could cause a kernel panic by reading certain sysfs attributes during a specific timing window, leading to a denial of service. There is no indication of privilege escalation or code execution. The impact is limited to system stability disruption via a NULL pointer dereference.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, avoid triggering the affected sysfs attributes during device online operations in the s390/dasd subsystem. Monitor vendor channels for official patches or updates.
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against unallocated private data… (CVE-2026-89457)
Description
A vulnerability in the Linux kernel s390/dasd subsystem was resolved that involved sysfs discipline callbacks dereferencing unallocated private data. Specifically, during the dasd_generic_set_online() process, discipline callbacks accessed device->private before it was allocated, causing a NULL pointer dereference and kernel panic. The fix involved guarding these dereferences to prevent accessing uninitialized memory.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel s390/dasd subsystem had a vulnerability where several sysfs show/store handlers called discipline callbacks that dereferenced device->private before it was allocated. This occurred because the discipline was assigned prior to check_device() allocating device->private during dasd_generic_set_online(). An unprivileged user could trigger a NULL pointer dereference by reading world-readable sysfs attributes in this timing window, resulting in a kernel panic. The vulnerability was fixed by adding guards around the dereferences inside each affected callback.
Potential Impact
An unprivileged user could cause a kernel panic by reading certain sysfs attributes during a specific timing window, leading to a denial of service. There is no indication of privilege escalation or code execution. The impact is limited to system stability disruption via a NULL pointer dereference.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, avoid triggering the affected sysfs attributes during device online operations in the s390/dasd subsystem. Monitor vendor channels for official patches or updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-94gp-p6v7-5m5q
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89457"]
Threat ID: 6aa4a02455bf5e2cf5a869b3
Added to database: 09/12/2026, 00:43:16 UTC
Last enriched: 09/12/2026, 01:17:23 UTC
Last updated: 09/12/2026, 01:17:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.