Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chain
Impact
The error path of the vfio-pci dma-buf export falls through the whole unwind chain after the dma-buf was already exported, producing a double free of the allocated objects and an unbalanced reference count on the vfio device itself. A tenant that can steer the export into its error path gets a double free in the kernel - the classic starting point for host privilege escalation - and can drop the device's refcount below what is live.
Who can reach it
A tenant holding /dev/vfio/<group> calls the dma-buf export ioctl while its own file-descriptor table is exhausted, which it controls simply by opening files up to RLIMIT_NOFILE. That makes the 'unlikely' fd-allocation failure a deliberate, repeatable trigger rather than a rare accident. Conditional on the vfio-pci dma-buf export feature being available; no host privilege.
What to do
Update to a stable kernel carrying commits 83ad334a / e98137f0. Interim: do not enable the vfio-pci dma-buf export feature for tenant devices, and cap per-container file-descriptor limits so the error path is harder to reach on demand.
References
Related entries
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostCVE-2022-49219 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabledCVE-2024-27437 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): An uninitialized stack variable is used as the device count when a tenant asks vfioCVE-2024-41052 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could changeCVE-2026-64476 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeCVE-2026-53322 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.