PT-2026-98658 · Linux · Linux
CVE-2026-97994
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vhost/vdpa: reject VRING NUM larger than device max
vhost vring set num() accepts any non-zero power-of-two queue size that
fits in 16 bits. vhost-vdpa then passes that value to set vq num()
without comparing it with get vq num max().
A process with access to /dev/vhost-vdpa-* can therefore configure a
queue larger than the device advertises. With vdpa sim, the worker can
walk descriptors beyond the mapped descriptor ring. KASAN reports a
16-byte out-of-bounds read, corresponding to one vring desc, in the
vringh IOTLB path:
BUG: KASAN: out-of-bounds in copy from iter
Read of size 16
copy from iotlb
copydesc iotlb
vringh getdesc iotlb
vdpasim net work
Cache get vq num max() immediately after reset. Some backends derive
it from writable queue-size state, so querying it after SET NUM may
return the current size instead of the device capability. Invalidate
the cached value before reset so a failed reset leaves SET NUM
disabled.
For VHOST SET VRING NUM, copy the complete vring state once and use
the same index and size for validation, vq->num, and set vq num().
This ensures that validation and use operate on the same copied values.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux