PT-2026-98660 · Linux · Linux
CVE-2026-97996
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio: fix use-after-free in unregister virtio device()
device unregister() is device del() plus put device(). When the caller
holds no extra reference, that drops the last one and runs the release
callback, which for several transports frees the memory the embedded
struct virtio device sits in. unregister virtio device() then calls
virtio debug device exit(), which reads dev->debugfs dir out of the freed
object.
Affected transports are the ones whose release callback frees and whose
remove path takes no reference: virtio mmio, virtio vdpa, virtio uml,
mlxbf-tmfifo and virtio ccw. virtio pci is unaffected because
virtio pci remove() brackets the call with get device() and put device().
Remove the debugfs entries before the device can go away. They are only
accessed through the protected debugfs interface, so
debugfs remove recursive() waits for in-progress file operations before
returning. Tearing them down while the device is still alive is therefore
safe.
Reproduced on User-Mode Linux with CONFIG KASAN and CONFIG VIRTIO DEBUG
by unbinding a virtio-uml device:
BUG: KASAN: slab-use-after-free in virtio debug device exit+0x36/0x4d
Read of size 8 at addr 00000000616e0b10 by task init/1
asan report load8 noabort
virtio debug device exit+0x36/0x4d
unregister virtio device+0x48/0x75
virtio uml remove
platform remove
device release driver internal
unbind store
Freed by task 1:
kfree
virtio uml release dev
device release
kobject put
put device
device unregister
With this applied, the report is gone and unbind is clean.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux