PT-2026-98658 · Linux · Linux

CVE-2026-97994

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vhost/vdpa: reject VRING NUM larger than device max
vhost vring set num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to set vq num() without comparing it with get vq num max().
A process with access to /dev/vhost-vdpa-* can therefore configure a queue larger than the device advertises. With vdpa sim, the worker can walk descriptors beyond the mapped descriptor ring. KASAN reports a 16-byte out-of-bounds read, corresponding to one vring desc, in the vringh IOTLB path:
BUG: KASAN: out-of-bounds in copy from iter Read of size 16 copy from iotlb copydesc iotlb vringh getdesc iotlb vdpasim net work
Cache get vq num max() immediately after reset. Some backends derive it from writable queue-size state, so querying it after SET NUM may return the current size instead of the device capability. Invalidate the cached value before reset so a failed reset leaves SET NUM disabled.
For VHOST SET VRING NUM, copy the complete vring state once and use the same index and size for validation, vq->num, and set vq num(). This ensures that validation and use operate on the same copied values.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97994

Affected Products

Linux