Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio): Vfio deleted the device before removing its debugfs tree, so debugfs files stay visible
Impact
Vfio deleted the device before removing its debugfs tree, so debugfs files stay visible while the devres-allocated state behind them has already been released. Anything that opens those files during the unregister window - which lasts as long as userspace still holds references to the device - reads through a stale inode private pointer into freed memory.
Who can reach it
Needs host root or whatever principal can read /sys/kernel/debug/vfio, and needs the read to land inside the unregister window of a device that a tenant is still holding open. Not tenant-reachable in a normal container (debugfs is not mounted there); the realistic trigger is host monitoring or debugging tooling that walks vfio debugfs while devices are being torn down.
What to do
Update to a stable kernel carrying commits 6cc60b41 / a53109ff. Interim: do not mount debugfs on production tenant nodes, or keep monitoring agents off /sys/kernel/debug/vfio while devices are unbinding.
References
Related entries
- Linux kernel (drivers/vfio): Pinned-memory accounting for a VFIO container is lost across exec(), then underflows to aCVE-2023-53171 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): A blocked migration-state transition makes the vfio state machine spin forever whileCVE-2026-64474 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): VFIO core advertised migration ioctls for devices whose driver never actually initialisedCVE-2022-50117 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): An uninitialized pointer in the VFIO group structure is dereferenced from a group ioctlCVE-2023-54174 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/vfio): Uninitialized kernel stack bytes sitting in a structure hole are copied out to userspaceCVE-2023-54137 · Linux kernel (drivers/vfio)Medium
- OpenSSH: use-after-free in the ssh client when remote-forwarding operations run concurrentlyCVE-2026-73282 · OpenSSH ssh client (concurrent remote port-forwarding operations)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.