From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CB756582BBA for ; Fri, 11 Sep 2026 19:51:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156284; cv=none; b=p11WBUJGNIn11zOi3nKmDquSXJE0j1bCUsBvMugDnJ9IKW1hlvfamEje13huqi3AJxydP2op2TJC6f+DrgfUOdoj2sspk60b9n20XH7jUDb2DjHW9EAd49IMJLk1+J4SitnyoLIUREvGDXT02yoR5o9sLpnrn4PooSpQE3dsVsM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156284; c=relaxed/simple; bh=5OG3t1b0nu1TQ8fPggwDQcVtmhRW75ABOzkytLiQR70=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=nG4e+5dzl8Qmb2PBy0vvBNkLCqdZHzIBsv/BVQHBD/+3m/W4vHomkYYYXB4ydn+VnczvRNvQRo7TL03GVSNVwbJ5oO0w8kriFn0PBQkoxNPxKrYHmkLQGyTL26ADdIh8dSr6tyut1U85kBiRXJm7V6FHCnHn4V7rXRQDV6qyvws= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=iW5/2uUu; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="iW5/2uUu" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8A9091F000FF; Fri, 11 Sep 2026 19:51:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156266; bh=FRd8Wqkqwpu+5DcgRXbJhtMkTLx1x+yUt8CGeHTjfhI=; h=From:To:Cc:Subject:Date:Reply-To; b=iW5/2uUubNMMftaoFPCJoDf/bfImkX1Cxhjp1DQLE6oo9S+9qVNrcUYjs8o7elSlk HjuRwWPzTQlvL19p0fj2Hglawoq69YREtp9LhaAr/qjKSNdY6ssmqOgUZy0aqUMGT3 8qqJBW/KQruZjdsRNSt4KebfPTU7Jutk+gg+oPbE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89459: s390/percpu: Fix MVIY_PERCPU() with older binutils Date: Fri, 11 Sep 2026 21:42:28 +0200 Message-ID: <2026091100-CVE-2026-89459-2349@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2946; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=0NtGhSlfSNHczNbpSYMssa/uEnp/50YQ/DZyP20tgXM=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIn3Oiay9qa0qHzFv00zLXZXmac47+RlLv3OdCemYq 1u0V/p4RywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzkVznDPOuH/pteWt1af7uE lYXF1mX7Et82JoYF83+fYlmnlnryqppN/oWzszbeEzXNBwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are already C string literals. This generates an assembler macro invocation with whitespace-separated quoted arguments: GEN_MVIY "459712" "%r3" GNU as versions prior to binutils 2.39 drop the separating whitespace between quoted macro arguments during input scrubbing. They consequently parse the invocation as a single argument and emit repeated warnings: Warning: missing closing `"' The .ifc in GEN_MVIY never matches and GNU as exits successfully without emitting the mviy instruction. As a result, the interrupted per-CPU sequence is not marked in lowcore and the exception return path cannot repair the per-CPU address register after migration. All MVIY_PERCPU() callers pass C string literals. Use them directly and separate the assembler macro arguments with an explicit comma. The resulting invocation is: GEN_MVIY 459712, %r3 This form is unambiguous for GNU as and LLVM's integrated assembler. This behavior was fixed in GNU as from binutils 2.39, but Linux supports binutils 2.30. The Linux kernel CVE team has assigned CVE-2026-89459 to this issue. Affected and fixed versions =========================== Issue introduced in 7.2 with commit a737737cdb9c94e40a9926cdc2320f874c05d709 and fixed in 7.2.4 with commit 91770b08a120967077ae78600612f18bc5ee3caf Issue introduced in 7.2 with commit a737737cdb9c94e40a9926cdc2320f874c05d709 and fixed in 7.3-rc1 with commit 101782f8945a125044347312d74d488c05741c4a Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89459 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: arch/s390/include/asm/percpu.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/91770b08a120967077ae78600612f18bc5ee3caf https://git.kernel.org/stable/c/101782f8945a125044347312d74d488c05741c4a