Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): If vfio-pci device registration fails after the device joined the VGA arbiter, the
Impact
If vfio-pci device registration fails after the device joined the VGA arbiter, the arbiter keeps a callback registered against a vfio device cookie that is about to be freed. The VGA arbiter then calls into freed state on the next arbitration - a use-after-free on a node where a GPU failed to bind for passthrough, and the upstream note is explicit that it becomes exploitable again as soon as the callback follows drvdata.
Who can reach it
Requires a vfio-pci registration failure on a VGA-class device, so the trigger is host-side provisioning: binding a GPU to vfio-pci where a later registration step fails. Not tenant-initiated. Reachable only on devices that participate in VGA arbitration, which in practice means display-capable GPUs rather than headless datacenter accelerators.
What to do
Update to a stable kernel carrying commits 0f2a35a0 / 8d65decd (5.10.261 / 5.12 / 5.13 are listed by the CNA for older branches). Interim: treat any vfio-pci bind failure on a VGA-capable GPU as requiring a node reboot before the device is offered to a tenant.
References
Related entries
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soCVE-2024-26810 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): A tenant holding a passthrough PCI device can make the kernel signal an interruptCVE-2024-26812 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Out-of-bounds read past the ecap_perms table when a tenant touches emulated PCIeCVE-2024-53214 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): The error path of the vfio-pci dma-buf export falls through the whole unwind chainCVE-2026-31468 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostCVE-2022-49219 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): For passthrough devices whose INTx has to be masked at the irqchip, the IRQ is enabledCVE-2024-27437 · Linux kernel (drivers/vfio/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.