CVE-2026-80921
HIGH
Published Sep 9, 2026
Modified Sep 10, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: vsie: zero stale crypto bits When shadowing crypto access bits from a format0 apcb (crycb 0 or 1), the bits 64..255 are unchanged from whatever is in the vsie page in the crycb and thus in the apcb. This gives a nested guest potential access to a device no longer available. Zero out the remaining bits.
Is your site exposed to CVE-2026-80921?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
8.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — Exploit Prediction
0.0013
Probability of exploitation
0.03%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733
https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6
https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b
https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d
https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf
https://git.kernel.org/stable/c/935eeba276012916c76243e5cbb843efd8fdb75d
https://git.kernel.org/stable/c/d110b3297f11ef227098b8a82ade2d5f123b7d2f
https://git.kernel.org/stable/c/d4bcd2df6d0d2af916b4fe1a533958778ea7c45b
https://git.kernel.org/stable/c/f6079dca67eccb5eabef9f72437948c66dc5131f
Frequently Asked Questions
What is CVE-2026-80921? +
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: vsie: zero stale crypto bits
When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested guest potential access
to a device no longer available. Zero out the remaining bits. It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2026-80921? +
CVE-2026-80921 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching. The EPSS score is 0.0013, placing it in the 0th percentile for exploitation probability.
How do I check if I'm vulnerable to CVE-2026-80921? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.