PT-2026-98657 · Linux · Linux

CVE-2026-97993

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vhost-vdpa: don't install the eventfd ctx fdget() error in config ctx
vhost vdpa set config call() swaps the eventfd ctx fdget() return value into v->config ctx before checking it, so on failure the field briefly holds an ERR PTR:
ctx = fd == VHOST FILE UNBIND ? NULL : eventfd ctx fdget(fd);
swap(ctx, v->config ctx);

if (!IS ERR OR NULL(ctx))
	eventfd ctx put(ctx);

if (IS ERR(v->config ctx)) {
	long ret = PTR ERR(v->config ctx);

	v->config ctx = NULL;
	return ret;
}
Commit 0bde59c1723a ("vhost-vdpa: set v->config ctx to NULL if eventfd ctx fdget() fails") added that clearing, and spelled out the invariant the rest of the file relies on: "we consider 'v->config ctx' valid if it is not NULL". The window between the swap and the clearing still breaks it. vhost vdpa config cb() only tests for NULL, so a config interrupt delivered inside the window hands the ERR PTR to eventfd signal().
Check the fd before installing it instead. That closes the window and matches how vhost vring ioctl() handles the same failure for the vq call fd.
It also stops a rejected fd from tearing down a config interrupt that was working: until now the swap replaced the live context and put it, so after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97993

Affected Products

Linux