PT-2026-104970 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
virtio-fs: avoid double-free on failed queue setup
virtio fs setup vqs() allocates fs->vqs and fs->mq map before calling virtio find vqs(). If virtio find vqs() fails, the error path frees both pointers and returns an error to virtio fs probe().
virtio fs probe() then drops the last kobject reference, and virtio fs ktype release() frees fs->vqs and fs->mq map again. This leaves dangling pointers in struct virtio fs and can trigger a double-free during probe failure cleanup.
Set fs->vqs and fs->mq map to NULL immediately after kfree() in the virtio fs setup vqs() error path so that the later kobject release sees an uninitialized state and kfree(NULL) becomes harmless.
This can be reproduced when a broken virtio-fs device advertises more request queues than the transport actually provides. In that case virtio find vqs() fails while setting up the extra queue, and the probe path reaches the double-free cleanup sequence.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-103925

Produtos afetados

Kernel