LiveActive security incident?Get immediate response
CVE Record

CVE-2025-71155: KVM: s390: Fix gmap_helper_zap_one_page() again

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A few checks were missing in gmap_helper_zap_one_page(), which can lead to memory corruption in the guest under specific circumstances. Add the missing checks.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue affects KVM on s390 systems. Missing checks in a memory-management helper can cause guest memory corruption under specific circumstances. The public bundle does not provide a CVSS score, exploitability details, or broad product impact, so urgency depends on whether you run Linux KVM on s390.

Executive priority

Medium priority for organizations operating s390 KVM virtualization; low operational urgency otherwise. Because severity and exploitability are not scored in the bundle, focus first on asset identification and vendor patch confirmation before emergency action.

Technical view

CVE-2025-71155 is a Linux kernel KVM s390 flaw in gmap_helper_zap_one_page(). The fix adds missing checks after prior work in the same area. The documented impact is guest memory corruption under specific circumstances. The affected-version metadata in the bundle is incomplete and should be validated against kernel stable commits and vendor builds.

Likely exposure

Exposure appears limited to Linux systems using KVM on s390 architecture. Organizations without s390 KVM virtualization are unlikely to be exposed based on the supplied description. Kernel versions and downstream vendor packages need confirmation against the referenced stable fixes.

Exploitation context

The source bundle does not report active exploitation and marks KEV as false. It also does not describe proof-of-concept availability, attack prerequisites, privileges, or whether corruption can cross guest boundaries. Treat exploitability as unconfirmed from these sources.

Researcher notes

The available record is terse. Key gaps are CVSS, CWE, precise affected-version boundaries, exploitability prerequisites, and whether corruption is confined to the guest. Do not infer host escape or active exploitation from the supplied description.

Mitigation direction

  • Identify Linux hosts running KVM on s390 architecture.
  • Check vendor kernel advisories for CVE-2025-71155 coverage.
  • Apply kernel updates containing the referenced stable fixes.
  • Prioritize systems hosting sensitive or multi-tenant guests.
  • Track downstream distribution backports, not only upstream version numbers.

Validation and detection

  • Confirm whether each virtualization host is s390 and uses KVM.
  • Map running kernel builds to vendor advisory status.
  • Check whether referenced stable commits are included or backported.
  • Review guest memory-corruption incidents on affected hosts.
  • Document non-s390 systems as out of scope for this CVE.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-71155 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
3Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux5deafa27d9ae040b75d392f60b12e300b42b4792, 5deafa27d9ae040b75d392f60b12e300b42b4792, 919efcadb63fc3d3a82c3de7194140e0b28903dc, 6.17.4unaffected
LinuxLinux6.18, 0, 6.18.4, 6.19affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.