PT-2026-104970 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio-fs: avoid double-free on failed queue setup
virtio fs setup vqs() allocates fs->vqs and fs->mq map before calling virtio find vqs(). If virtio find vqs() fails, the error path frees both pointers and returns an error to virtio fs probe().
virtio fs probe() then drops the last kobject reference, and virtio fs ktype release() frees fs->vqs and fs->mq map again. This leaves dangling pointers in struct virtio fs and can trigger a double-free during probe failure cleanup.
Set fs->vqs and fs->mq map to NULL immediately after kfree() in the virtio fs setup vqs() error path so that the later kobject release sees an uninitialized state and kfree(NULL) becomes harmless.
This can be reproduced when a broken virtio-fs device advertises more request queues than the transport actually provides. In that case virtio find vqs() fails while setting up the extra queue, and the probe path reaches the double-free cleanup sequence.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103925

Affected Products

Kernel