PT-2026-98818 · Linux · Linux Kernel
CVE-2026-98156
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.8 and 6.18 LTS
Description
An issue exists in the drm/virtio component where the
virtio-gpu driver fails to correctly use the DMA API for resource backing on Xen PV domains. In these domains, page addresses do not correspond to the real machine addresses used by the host. Because the virtio-gpu implementation only checks the feature bit and ignores the xen domain() status, the virtio gpu object shmem init() function describes framebuffer backing pages using sg phys(). This results in the host accessing guest-physical addresses that may belong to other domains, leading to the scanning of unrelated memory. The issue is specifically present in PV domains, while PVH domains remain unaffected due to identity-mapping.Recommendations
For Linux kernel versions 6.8 and 6.18 LTS, update the kernel to a version where the
virtio gpu use dma api() function includes the xen domain() check to ensure the DMA API is used for resource backing.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel