Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio): Uninitialized kernel stack bytes sitting in a structure hole are copied out to userspace
Impact
Uninitialized kernel stack bytes sitting in a structure hole are copied out to userspace through the VFIO container's info ioctl. A tenant reads back kernel stack contents it was never meant to see - small on its own, but exactly the kind of leak used to infer layout or recover a pointer before a heavier bug is fired.
Who can reach it
Any tenant holding /dev/vfio/vfio calling VFIO_IOMMU_GET_INFO on its own container. One ioctl, no race, no host root, no hardware precondition beyond the legacy type1 container being in use.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: drop /dev/vfio from containers that do not need passthrough - there is no way to filter a single capability out of the info ioctl.
References
Related entries
- Linux kernel (drivers/vfio): Vfio deleted the device before removing its debugfs tree, so debugfs files stay visibleCVE-2026-64473 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): Pinned-memory accounting for a VFIO container is lost across exec(), then underflows to aCVE-2023-53171 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): A blocked migration-state transition makes the vfio state machine spin forever whileCVE-2026-64474 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): VFIO core advertised migration ioctls for devices whose driver never actually initialisedCVE-2022-50117 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): An uninitialized pointer in the VFIO group structure is dereferenced from a group ioctlCVE-2023-54174 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/iommu/iommufd): The iommufd dirty-tracking bitmap computed an index by shifting a 32-bit constantCVE-2025-21724 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.