Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/cdx): VFIO_DEVICE_SET_IRQS was not serialized, so two concurrent interrupt-configuration
Impact
VFIO_DEVICE_SET_IRQS was not serialized, so two concurrent interrupt-configuration ioctls can have one caller operating on the MSI interrupt array while the other frees it. That is a use-after-free reached directly through the device fd's interrupt-setup ioctl - the textbook shape of a vfio interrupt-index bug, and it lands with tenant-controlled timing.
Who can reach it
Two threads inside a tenant container holding the vfio device fd issue VFIO_DEVICE_SET_IRQS concurrently - one enabling MSI, one disabling. No host privilege and no guest needed. Hardware-conditional: vfio-cdx binds to the AMD/Xilinx CDX bus on Versal-class SoCs, so this is not reachable on x86 or standard Arm GPU nodes. Carry it as a pattern to check for in the PCI SET_IRQS path rather than as a live exposure on a GPU fleet.
What to do
Update to a stable kernel carrying commits ddf96e23 / 7b436ade on any CDX-bus platform. No action needed on x86/Arm GPU nodes that do not build or load vfio-cdx; confirm with lsmod that vfio-cdx is absent.
References
Related entries
- Linux kernel (drivers/vfio/cdx): A tenant can call the interrupt-configuration ioctl with the trigger flags before MSICVE-2026-46034 · Linux kernel (drivers/vfio/cdx)Medium
- Linux kernel (net/xfrm): SA deletion decided whether to unhash from the by-SPI and by-sequence chains using fieldCVE-2026-46116 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/net/ethernet/mellanox/mlx4): Shared receive queue objects are looked up from an asynchronousCVE-2026-46181 · Linux kernel (drivers/net/ethernet/mellanox/mlx4)High
- Linux kernel vmw_pvrdma: double free on ucontext allocation error pathCVE-2026-46189 · Linux kernel vmw_pvrdma driver (pvrdma_alloc_ucontext error path)High
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2026-46197 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- virtio-win Viosock: integer overflow in the select IOCTL overflows a NonPagedPool array and escalates in the guestCVE-2026-46655 · virtio-win Viosock driver (IOCTL_SELECT, VIOSockSelect bounds check)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.