Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): Out-of-bounds read past the ecap_perms table when a tenant touches emulated PCIe
Impact
Out-of-bounds read past the ecap_perms table when a tenant touches emulated PCIe extended config space on a device whose first extended capability has to be hidden. That table is the policy that decides which config-space writes vfio lets through to real hardware, so indexing off the end means a tenant's config accesses are policed by whatever kernel bytes follow it - the emulation boundary that keeps a passthrough device inside its assignment.
Who can reach it
A tenant holding the vfio-pci device fd, doing ordinary reads/writes on the device's config-space region. No race, no special ioctl - the only precondition is a passthrough device whose first PCIe extended capability ID is above PCI_EXT_CAP_ID_MAX (an unknown or deliberately hidden capability), which vfio then has to mask by zeroing the ID in place. No host root required.
What to do
The record lists no fixed release; boot a kernel carrying the stable fix commits below. Interim controls: audit the extended capability list of the device models you pass through, and drop /dev/vfio device nodes from containers that do not need them.
References
Related entries
- Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chainCVE-2026-31468 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostCVE-2022-49219 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabledCVE-2024-27437 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): An uninitialized stack variable is used as the device count when a tenant asks vfioCVE-2024-41052 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could changeCVE-2026-64476 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.