Database/Kernel, userspace & hypervisor

Linux KVM - irqfd routing type clobbered on deassign: Deassigning a KVM_IRQFD clobbers the irqfd's copy of the
Impact
Deassigning a KVM_IRQFD clobbers the irqfd's copy of the interrupt routing entry, leaving stale or wrong routing behind. Interrupt routing decides which guest receives which interrupt, so corrupting it on teardown is a cross-VM correctness failure on the interrupt path - and on a GPU host, irqfd is exactly how passed-through accelerator interrupts reach their guest.
Who can reach it
Through the KVM ioctl interface, from the VMM process managing guests - reachable when devices are hot-unplugged or VMs torn down.
What to do
Fixed in the Linux kernel. Distro kernel update plus host reboot; no firmware step. Relevant to any fleet doing GPU passthrough with dynamic device attach/detach.
References
Related entries
- Linux kernel (net/xfrm): Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback canCVE-2026-23239 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/iommu): Unbinding shared virtual addressing touches the mm's IOMMU state after the domain-freeCVE-2026-23429 · Linux kernel (drivers/iommu)High
- Linux kernel (net/xfrm): Flushing xfrm states during namespace cleanup re-arms the NAT-keepalive delayed work after itCVE-2026-31406 · Linux kernel (net/xfrm)High
- Linux kernel (crypto algif_aead): Incorrect resource transfer between spheres in algif_aead (reverted to out-of-placeCVE-2026-31431 · Linux kernel (crypto algif_aead)High
- Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chainCVE-2026-31468 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.