PT-2026-98660 · Linux · Linux

CVE-2026-97996

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
virtio: fix use-after-free in unregister virtio device()
device unregister() is device del() plus put device(). When the caller holds no extra reference, that drops the last one and runs the release callback, which for several transports frees the memory the embedded struct virtio device sits in. unregister virtio device() then calls virtio debug device exit(), which reads dev->debugfs dir out of the freed object.
Affected transports are the ones whose release callback frees and whose remove path takes no reference: virtio mmio, virtio vdpa, virtio uml, mlxbf-tmfifo and virtio ccw. virtio pci is unaffected because virtio pci remove() brackets the call with get device() and put device().
Remove the debugfs entries before the device can go away. They are only accessed through the protected debugfs interface, so debugfs remove recursive() waits for in-progress file operations before returning. Tearing them down while the device is still alive is therefore safe.
Reproduced on User-Mode Linux with CONFIG KASAN and CONFIG VIRTIO DEBUG by unbinding a virtio-uml device:
BUG: KASAN: slab-use-after-free in virtio debug device exit+0x36/0x4d Read of size 8 at addr 00000000616e0b10 by task init/1 asan report load8 noabort virtio debug device exit+0x36/0x4d unregister virtio device+0x48/0x75 virtio uml remove platform remove device release driver internal unbind store
Freed by task 1: kfree virtio uml release dev device release kobject put put device device unregister
With this applied, the report is gone and unbind is clean.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97996

Affected Products

Linux