PT-2026-98658 · Linux · Linux

CVE-2026-97994

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
vhost/vdpa: reject VRING NUM larger than device max
vhost vring set num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to set vq num() without comparing it with get vq num max().
A process with access to /dev/vhost-vdpa-* can therefore configure a queue larger than the device advertises. With vdpa sim, the worker can walk descriptors beyond the mapped descriptor ring. KASAN reports a 16-byte out-of-bounds read, corresponding to one vring desc, in the vringh IOTLB path:
BUG: KASAN: out-of-bounds in copy from iter Read of size 16 copy from iotlb copydesc iotlb vringh getdesc iotlb vdpasim net work
Cache get vq num max() immediately after reset. Some backends derive it from writable queue-size state, so querying it after SET NUM may return the current size instead of the device capability. Invalidate the cached value before reset so a failed reset leaves SET NUM disabled.
For VHOST SET VRING NUM, copy the complete vring state once and use the same index and size for validation, vq->num, and set vq num(). This ensures that validation and use operate on the same copied values.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97994

Produtos afetados

Linux