PT-2026-104970 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio-fs: avoid double-free on failed queue setup
virtio fs setup vqs() allocates fs->vqs and fs->mq map before calling
virtio find vqs(). If virtio find vqs() fails, the error path frees both
pointers and returns an error to virtio fs probe().
virtio fs probe() then drops the last kobject reference, and
virtio fs ktype release() frees fs->vqs and fs->mq map again. This leaves
dangling pointers in struct virtio fs and can trigger a double-free during
probe failure cleanup.
Set fs->vqs and fs->mq map to NULL immediately after kfree() in the
virtio fs setup vqs() error path so that the later kobject release sees an
uninitialized state and kfree(NULL) becomes harmless.
This can be reproduced when a broken virtio-fs device advertises more
request queues than the transport actually provides. In that case
virtio find vqs() fails while setting up the extra queue, and the probe
path reaches the double-free cleanup sequence.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel