PT-2026-98659 · Linux · Linux
CVE-2026-97995
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
virtio console: do not free control-out buffers on remove
send control msg() publishes &portdev->cpkt as the control-out
virtqueue cookie. remove vqs() walks every virtqueue and passes leftover
cookies to free buf(), which treats them as struct port buffer and
reads sgpages.
If a control message is still on c ovq when the device is unbound,
free buf() reads past the ports device object.
KASAN reported slab-out-of-bounds in free buf():
free buf
remove vqs
virtcons remove
unbind storeThe object was the ports device allocated in virtcons probe().
Drain c ovq without freeing. The packet lives in portdev and is released
with it.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux