PT-2026-98659 · Linux · Linux

CVE-2026-97995

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio console: do not free control-out buffers on remove
send control msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove vqs() walks every virtqueue and passes leftover cookies to free buf(), which treats them as struct port buffer and reads sgpages.
If a control message is still on c ovq when the device is unbound, free buf() reads past the ports device object.
KASAN reported slab-out-of-bounds in free buf():
free buf
remove vqs
virtcons remove
unbind store
The object was the ports device allocated in virtcons probe().
Drain c ovq without freeing. The packet lives in portdev and is released with it.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97995

Affected Products

Linux