Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabled
Impact
For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabled before vfio disables it, so an interrupt arriving in that window double-increments the disable depth. The line stays disabled with no way for the tenant to recover it through vfio, and where that IRQ line is shared with other devices on the host, they stop receiving interrupts too.
Who can reach it
A tenant holding a vfio-pci device fd enabling INTx, with the device asserting its interrupt inside the request_irq window. No host root, and the tenant does not have to win a tight race - it controls when the device asserts. Conditional on a passthrough function that lacks DisINTx support, which is what makes vfio use the exclusive masked-INTx path.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim controls: pass through only MSI/MSI-X-capable functions, and avoid assigning devices whose INTx line is shared with host-owned devices.
References
Related entries
- Linux kernel (drivers/vfio/pci): An uninitialized stack variable is used as the device count when a tenant asks vfioCVE-2024-41052 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could changeCVE-2026-64476 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeCVE-2026-53322 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Vfio-pci exports a dma-buf over BAR memory without confirming those BAR resources wereCVE-2026-64042 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): If vfio-pci device registration fails after the device joined the VGA arbiter, theCVE-2026-64475 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.