📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology HIGH 1h Global apt Government/Critical Infrastructure CRITICAL 3h Global vulnerability Enterprise Software / Data Analytics CRITICAL 4h Global vulnerability Artificial Intelligence and Technology HIGH 7h Global general Technology and Artificial Intelligence MEDIUM 10h Global general Technology and Artificial Intelligence HIGH 11h Global vulnerability Higher Education CRITICAL 21h Global data_breach Government HIGH 22h Global supply_chain Software Development and Open Source Communities CRITICAL 22h Global malware Software Development CRITICAL 22h Global supply_chain Software Development and Technology HIGH 1h Global apt Government/Critical Infrastructure CRITICAL 3h Global vulnerability Enterprise Software / Data Analytics CRITICAL 4h Global vulnerability Artificial Intelligence and Technology HIGH 7h Global general Technology and Artificial Intelligence MEDIUM 10h Global general Technology and Artificial Intelligence HIGH 11h Global vulnerability Higher Education CRITICAL 21h Global data_breach Government HIGH 22h Global supply_chain Software Development and Open Source Communities CRITICAL 22h Global malware Software Development CRITICAL 22h Global supply_chain Software Development and Technology HIGH 1h Global apt Government/Critical Infrastructure CRITICAL 3h Global vulnerability Enterprise Software / Data Analytics CRITICAL 4h Global vulnerability Artificial Intelligence and Technology HIGH 7h Global general Technology and Artificial Intelligence MEDIUM 10h Global general Technology and Artificial Intelligence HIGH 11h Global vulnerability Higher Education CRITICAL 21h Global data_breach Government HIGH 22h Global supply_chain Software Development and Open Source Communities CRITICAL 22h Global malware Software Development CRITICAL 22h
Vulnerabilities

CVE-2025-71155

High
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix gmap_helper_zap_one_page() again A few checks were missing in gmap_helper_zap_one_page(), which can lead to memory
CWE-787 — Weakness Type
Published: Jan 23, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: Fix gmap_helper_zap_one_page() again

A few checks were missing in gmap_helper_zap_one_page(), which can lead
to memory corruption in the guest under specific circumstances.

Add the missing checks.

🤖 AI Executive Summary

CVE-2025-71155 is a memory corruption vulnerability in the Linux kernel's KVM s390 implementation affecting the gmap_helper_zap_one_page() function. Missing validation checks can lead to guest memory corruption under specific circumstances. This vulnerability requires local access and affects systems running vulnerable Linux kernel versions on s390 architecture.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 28, 2026 07:52
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily affects Saudi organizations running KVM virtualization on s390 architecture systems, which is less common in typical Saudi enterprise environments but critical for: (1) Government data centers using IBM mainframe-based virtualization for sensitive applications, (2) Large financial institutions (SAMA-regulated banks) utilizing s390 systems for core banking infrastructure, (3) Telecommunications providers (STC, Mobily) running virtualized mainframe workloads. The memory corruption could lead to guest VM escape scenarios, compromising isolated workloads and potentially affecting multi-tenant environments.
🏢 Affected Saudi Sectors
Government Banking Telecommunications Data Centers Enterprise IT Infrastructure
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify systems running Linux kernel on s390 architecture with KVM enabled
2. Check kernel version against vulnerable versions (typically pre-6.x series with the unfixed gmap_helper_zap_one_page function)
3. Restrict local access to KVM hypervisor management interfaces

Patching Guidance:
1. Apply the latest Linux kernel security patch that includes the gmap_helper_zap_one_page() fix
2. Test patches in non-production environments first, particularly for critical banking/government systems
3. Schedule maintenance windows for kernel updates on production s390 systems
4. Verify patch application: grep 'gmap_helper_zap_one_page' in kernel changelog

Compensating Controls (if immediate patching not possible):
1. Implement strict access controls to KVM management interfaces
2. Disable KVM on non-essential s390 systems
3. Isolate s390 virtualization hosts on separate network segments
4. Monitor for unusual memory access patterns in guest VMs

Detection Rules:
1. Monitor kernel logs for memory corruption warnings or page fault anomalies
2. Alert on unexpected guest VM crashes or memory errors
3. Track unauthorized attempts to access KVM management interfaces
4. Monitor for guest-to-host escape attempts using SELinux/AppArmor logs
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد الأنظمة التي تقوم بتشغيل نواة لينكس على معمارية s390 مع تفعيل KVM
2. التحقق من إصدار النواة مقابل الإصدارات المعرضة للخطر
3. تقييد الوصول المحلي إلى واجهات إدارة KVM

إرشادات التصحيح:
1. تطبيق أحدث تصحيح أمان نواة لينكس يتضمن إصلاح gmap_helper_zap_one_page()
2. اختبار التصحيحات في بيئات غير الإنتاج أولاً
3. جدولة نوافذ الصيانة لتحديثات النواة على أنظمة s390 الإنتاجية
4. التحقق من تطبيق التصحيح

الضوابط البديلة:
1. تطبيق ضوابط وصول صارمة على واجهات إدارة KVM
2. تعطيل KVM على أنظمة s390 غير الأساسية
3. عزل مضيفي افتراضية s390 على قطاعات شبكة منفصلة
4. مراقبة أنماط الوصول غير العادية للذاكرة في الأجهزة الافتراضية الضيفة

قواعد الكشف:
1. مراقبة سجلات النواة للتحذيرات من تلف الذاكرة
2. التنبيه على أعطال الأجهزة الافتراضية غير المتوقعة
3. تتبع محاولات الوصول غير المصرح بها
4. مراقبة محاولات الهروب من الضيف إلى المضيف
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of access
🔵 SAMA CSF
SAMA CSF ID.RA-1 - Asset Management and Vulnerability Management SAMA CSF PR.IP-12 - System and Information Integrity SAMA CSF DE.CM-1 - Detection and Analysis
🟡 ISO 27001:2022
ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development, test and acceptance ISO 27001:2022 A.12.2.1 - Information and other assets associated with information processing facilities
📦 Affected Products / CPE 2 entries
linux:linux_kernel
linux:linux_kernel
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-787
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-01-23
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
patch-available CWE-787
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.