PT-2026-98659 · Linux · Linux
CVE-2026-97995
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio console: do not free control-out buffers on remove
send control msg() publishes &portdev->cpkt as the control-out
virtqueue cookie. remove vqs() walks every virtqueue and passes leftover
cookies to free buf(), which treats them as struct port buffer and
reads sgpages.
If a control message is still on c ovq when the device is unbound,
free buf() reads past the ports device object.
KASAN reported slab-out-of-bounds in free buf():
free buf
remove vqs
virtcons remove
unbind storeThe object was the ports device allocated in virtcons probe().
Drain c ovq without freeing. The packet lives in portdev and is released
with it.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux