CVE-2025-71155: KVM: s390: Fix gmap_helper_zap_one_page() again
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: Fix gmap_helper_zap_one_page() again
A few checks were missing in gmap_helper_zap_one_page(), which can lead
to memory corruption in the guest under specific circumstances.
Add the missing checks.
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue affects KVM on s390 systems. Missing checks in a memory-management helper can cause guest memory corruption under specific circumstances. The public bundle does not provide a CVSS score, exploitability details, or broad product impact, so urgency depends on whether you run Linux KVM on s390.
Executive priority
Medium priority for organizations operating s390 KVM virtualization; low operational urgency otherwise. Because severity and exploitability are not scored in the bundle, focus first on asset identification and vendor patch confirmation before emergency action.
Technical view
CVE-2025-71155 is a Linux kernel KVM s390 flaw in gmap_helper_zap_one_page(). The fix adds missing checks after prior work in the same area. The documented impact is guest memory corruption under specific circumstances. The affected-version metadata in the bundle is incomplete and should be validated against kernel stable commits and vendor builds.
Likely exposure
Exposure appears limited to Linux systems using KVM on s390 architecture. Organizations without s390 KVM virtualization are unlikely to be exposed based on the supplied description. Kernel versions and downstream vendor packages need confirmation against the referenced stable fixes.
Exploitation context
The source bundle does not report active exploitation and marks KEV as false. It also does not describe proof-of-concept availability, attack prerequisites, privileges, or whether corruption can cross guest boundaries. Treat exploitability as unconfirmed from these sources.
Researcher notes
The available record is terse. Key gaps are CVSS, CWE, precise affected-version boundaries, exploitability prerequisites, and whether corruption is confined to the guest. Do not infer host escape or active exploitation from the supplied description.
Mitigation direction
Identify Linux hosts running KVM on s390 architecture.
Check vendor kernel advisories for CVE-2025-71155 coverage.
Apply kernel updates containing the referenced stable fixes.
Prioritize systems hosting sensitive or multi-tenant guests.
Track downstream distribution backports, not only upstream version numbers.
Validation and detection
Confirm whether each virtualization host is s390 and uses KVM.
Map running kernel builds to vendor advisory status.
Check whether referenced stable commits are included or backported.
Review guest memory-corruption incidents on affected hosts.
Document non-s390 systems as out of scope for this CVE.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-71155 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
3Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Jan 23, 2026, 14:25 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.