PT-2026-104890 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virt: acrn: Fix irqfd use-after-free during eventfd shutdown
acrn irqfd deassign() and the eventfd EPOLLHUP wakeup can race and free the same struct hsm irqfd:
CPU0 CPU1

eventfd release() wake up poll(EPOLLHUP) hsm irqfd wakeup() queue work(&irqfd->shutdown) acrn irqfd deassign() hsm irqfd shutdown() list del init() eventfd ctx remove wait queue() eventfd ctx put() kfree(irqfd) hsm irqfd shutdown work() container of(work, ..., shutdown) irqfd->vm <-- use-after-free
The deassign path freed the irqfd while a shutdown work item was already queued by EPOLLHUP (or vice versa), so the work item could resurrect a dangling pointer through container of().
Switch to the lifetime model used by KVM irqfds:
  • Deassign/deinit only deactivate the irqfd: remove it from vm->irqfds under irqfds lock and queue the cleanup work.
  • hsm irqfd shutdown work() becomes the sole owner that unhooks the eventfd waitqueue entry, drops the eventfd reference and frees the irqfd.
  • A new HSM IRQFD FLAG SHUTDOWN bit guarded by test and set bit() ensures the cleanup work is queued at most once, no matter how many of {EPOLLHUP, deassign, deinit} fire concurrently. This is safe to call from the waitqueue callback, which runs with wqh->lock held and IRQs disabled and therefore cannot take irqfds lock.
  • acrn irqfd deassign() flushes vm->irqfd wq before returning so the eventfd is fully detached on return. acrn irqfd deinit() deactivates every irqfd, flushes the workqueue and only then destroys it, so no path can queue work() onto a torn-down workqueue.
  • acrn irqfd assign() now installs the eventfd waitqueue entry and publishes the irqfd to vm->irqfds under irqfds lock, so the irqfd is never visible to deassign/deinit before its waitqueue entry is in place, and any EPOLLHUP that fires in the assign window queues cleanup work that blocks on irqfds lock until publication is done.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103679

Affected Products

Kernel