PT-2026-98657 · Linux · Linux
CVE-2026-97993
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vhost-vdpa: don't install the eventfd ctx fdget() error in config ctx
vhost vdpa set config call() swaps the eventfd ctx fdget() return value
into v->config ctx before checking it, so on failure the field briefly
holds an ERR PTR:
ctx = fd == VHOST FILE UNBIND ? NULL : eventfd ctx fdget(fd);
swap(ctx, v->config ctx);
if (!IS ERR OR NULL(ctx))
eventfd ctx put(ctx);
if (IS ERR(v->config ctx)) {
long ret = PTR ERR(v->config ctx);
v->config ctx = NULL;
return ret;
}Commit 0bde59c1723a ("vhost-vdpa: set v->config ctx to NULL if
eventfd ctx fdget() fails") added that clearing, and spelled out the
invariant the rest of the file relies on: "we consider 'v->config ctx'
valid if it is not NULL". The window between the swap and the clearing
still breaks it. vhost vdpa config cb() only tests for NULL, so a config
interrupt delivered inside the window hands the ERR PTR to
eventfd signal().
Check the fd before installing it instead. That closes the window and
matches how vhost vring ioctl() handles the same failure for the vq call
fd.
It also stops a rejected fd from tearing down a config interrupt that was
working: until now the swap replaced the live context and put it, so
after an EBADF the device silently stopped delivering config interrupts
until userspace installed a new fd.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux