PT-2026-98657 · Linux · Linux
CVE-2026-97993
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vhost-vdpa: don't install the eventfd ctx fdget() error in config ctx
vhost vdpa set config call() swaps the eventfd ctx fdget() return value
into v->config ctx before checking it, so on failure the field briefly
holds an ERR PTR:
ctx = fd == VHOST FILE UNBIND ? NULL : eventfd ctx fdget(fd);
swap(ctx, v->config ctx);
if (!IS ERR OR NULL(ctx))
eventfd ctx put(ctx);
if (IS ERR(v->config ctx)) {
long ret = PTR ERR(v->config ctx);
v->config ctx = NULL;
return ret;
}Commit 0bde59c1723a ("vhost-vdpa: set v->config ctx to NULL if
eventfd ctx fdget() fails") added that clearing, and spelled out the
invariant the rest of the file relies on: "we consider 'v->config ctx'
valid if it is not NULL". The window between the swap and the clearing
still breaks it. vhost vdpa config cb() only tests for NULL, so a config
interrupt delivered inside the window hands the ERR PTR to
eventfd signal().
Check the fd before installing it instead. That closes the window and
matches how vhost vring ioctl() handles the same failure for the vq call
fd.
It also stops a rejected fd from tearing down a config interrupt that was
working: until now the swap replaced the live context and put it, so
after an EBADF the device silently stopped delivering config interrupts
until userspace installed a new fd.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux