Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): An uninitialized stack variable is used as the device count when a tenant asks vfio
Impact
An uninitialized stack variable is used as the device count when a tenant asks vfio which devices are in its PCI hot-reset group. The count returned is wrong and the caller crashes - and that same group enumeration is the data vfio works from when reasoning about which devices a bus reset would take with it.
Who can reach it
A tenant holding a vfio-pci device fd calling VFIO_DEVICE_GET_PCI_HOT_RESET_INFO. One plain ioctl, no race to win, no host root. Upstream's stated observable is a wrong device count and a userspace crash, not a demonstrated kernel write.
What to do
Update to 6.6.41 or 6.9.10 or later. Interim control: drop /dev/vfio device nodes from containers that do not need passthrough.
References
Related entries
- Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could changeCVE-2026-64476 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeCVE-2026-53322 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Vfio-pci exports a dma-buf over BAR memory without confirming those BAR resources wereCVE-2026-64042 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): If vfio-pci device registration fails after the device joined the VGA arbiter, theCVE-2026-64475 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soCVE-2024-26810 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.