In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: Fix memory leak in guest debug handling
bp_data is freed only for the error case by kfree(bp_data). Every successful KVM_SET_GUEST_DEBUG will leak bp_data.
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: Fix memory leak in guest debug handling
bp_data is freed only for the error case by kfree(bp_data). Every successful KVM_SET_GUEST_DEBUG will leak bp_data.
September 16, 2026
September 16, 2026
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.1.106-1 ... 7.2~rc7-1~exp1 (360 versions) |
| — |
| linux-6.12 | 6.12.100-1~deb12u1, 6.12.101-1~deb12u1, 6.12.107-1~deb12u1 |
| — |
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 6.12.96-1 (35 versions) |
| — |
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| linux | 6.12.100-1 ... 7.2~rc7-1~exp1 (179 versions) |
| — |
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-89925
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.