Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/fsl-mc): The eventfd trigger for a vfio-fsl-mc interrupt starts out NULL and becomes NULL
Impact
The eventfd trigger for a vfio-fsl-mc interrupt starts out NULL and becomes NULL again if the tenant sets it to -1, but the loopback test path fires the handler without checking. A tenant holding the device fd dereferences NULL in the kernel interrupt path and downs the host for everyone on the node.
Who can reach it
A container or VM holding a vfio-fsl-mc device fd, invoking the loopback interrupt trigger through VFIO_DEVICE_SET_IRQS before setting an eventfd or after clearing it to -1. No host root. Conditional on the NXP DPAA2 fsl-mc bus and its vfio driver - NXP SoC hardware, not present in x86 or ARM GPU fleets.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim control: blacklist vfio-fsl-mc on any fleet that does not assign DPAA2 objects.
References
Related entries
- Linux kernel (HID): Uninitialised HID report buffer leaks kernel memoryCVE-2024-50302 · Linux kernel (HID)Medium
- Linux kernel (drivers/pci/endpoint): Pci_epc_destroy() releases the PCI domain ID using a device object it has alreadyCVE-2024-56561 · Linux kernel (drivers/pci/endpoint)Medium
- Linux kernel (drivers/pci/endpoint): The endpoint function core calls list_del() on a structure that is a list HEADCVE-2025-39783 · Linux kernel (drivers/pci/endpoint)Medium
- Linux kernel (drivers/vfio/cdx): A tenant can call the interrupt-configuration ioctl with the trigger flags before MSICVE-2026-46034 · Linux kernel (drivers/vfio/cdx)Medium
- OpenSSH client X11 forwarding: a local user can pre-bind the X socket and hijack a forwarded sessionCVE-2026-55655 · OpenSSH client X11 forwarding (abstract UNIX X socket pre-binding)Medium
- Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.x: Proof that interrupt remapping is not a completeCVE-2013-3495 · Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.xMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.