PT-2026-98660 · Linux · Linux

CVE-2026-97996

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
virtio: fix use-after-free in unregister virtio device()
device unregister() is device del() plus put device(). When the caller holds no extra reference, that drops the last one and runs the release callback, which for several transports frees the memory the embedded struct virtio device sits in. unregister virtio device() then calls virtio debug device exit(), which reads dev->debugfs dir out of the freed object.
Affected transports are the ones whose release callback frees and whose remove path takes no reference: virtio mmio, virtio vdpa, virtio uml, mlxbf-tmfifo and virtio ccw. virtio pci is unaffected because virtio pci remove() brackets the call with get device() and put device().
Remove the debugfs entries before the device can go away. They are only accessed through the protected debugfs interface, so debugfs remove recursive() waits for in-progress file operations before returning. Tearing them down while the device is still alive is therefore safe.
Reproduced on User-Mode Linux with CONFIG KASAN and CONFIG VIRTIO DEBUG by unbinding a virtio-uml device:
BUG: KASAN: slab-use-after-free in virtio debug device exit+0x36/0x4d Read of size 8 at addr 00000000616e0b10 by task init/1 asan report load8 noabort virtio debug device exit+0x36/0x4d unregister virtio device+0x48/0x75 virtio uml remove platform remove device release driver internal unbind store
Freed by task 1: kfree virtio uml release dev device release kobject put put device device unregister
With this applied, the report is gone and unbind is clean.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-97996

Produtos afetados

Linux