PT-2026-104890 · Azure Linux · Kernel
Publicado
2026-09-24
·
Atualizado
2026-09-24
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
virt: acrn: Fix irqfd use-after-free during eventfd shutdown
acrn irqfd deassign() and the eventfd EPOLLHUP wakeup can race and free
the same struct hsm irqfd:
CPU0 CPU1
eventfd release()
wake up poll(EPOLLHUP)
hsm irqfd wakeup()
queue work(&irqfd->shutdown)
acrn irqfd deassign()
hsm irqfd shutdown()
list del init()
eventfd ctx remove wait queue()
eventfd ctx put()
kfree(irqfd)
hsm irqfd shutdown work()
container of(work, ..., shutdown)
irqfd->vm <-- use-after-free
The deassign path freed the irqfd while a shutdown work item was
already queued by EPOLLHUP (or vice versa), so the work item could
resurrect a dangling pointer through container of().
Switch to the lifetime model used by KVM irqfds:
- Deassign/deinit only deactivate the irqfd: remove it from vm->irqfds under irqfds lock and queue the cleanup work.
- hsm irqfd shutdown work() becomes the sole owner that unhooks the eventfd waitqueue entry, drops the eventfd reference and frees the irqfd.
- A new HSM IRQFD FLAG SHUTDOWN bit guarded by test and set bit() ensures the cleanup work is queued at most once, no matter how many of {EPOLLHUP, deassign, deinit} fire concurrently. This is safe to call from the waitqueue callback, which runs with wqh->lock held and IRQs disabled and therefore cannot take irqfds lock.
- acrn irqfd deassign() flushes vm->irqfd wq before returning so the eventfd is fully detached on return. acrn irqfd deinit() deactivates every irqfd, flushes the workqueue and only then destroys it, so no path can queue work() onto a torn-down workqueue.
- acrn irqfd assign() now installs the eventfd waitqueue entry and publishes the irqfd to vm->irqfds under irqfds lock, so the irqfd is never visible to deassign/deinit before its waitqueue entry is in place, and any EPOLLHUP that fires in the assign window queues cleanup work that blocks on irqfds lock until publication is done.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel