Database/Kernel, userspace & hypervisor
Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel buffer
Impact
virtio_get_edid_block() checks the read offset only against the device-supplied resp->size and never against the fixed-size resp->edid array, while the block index comes from the device-supplied extension count. A virtio-gpu backend that advertises a large size together with a high block count makes the guest kernel read well past the array into adjacent kernel memory, and the bytes come back out through the parsed EDID — an out-of-bounds read and information leak, with the record's vector also claiming an availability impact. Note the trust boundary this needs: in a conventional cloud the hypervisor already owns the guest, so this only buys an attacker something where the device model is outside the guest's trust boundary — a confidential VM, or a virtio-gpu backend running as a separate, less-trusted process. The record describes a malicious backend and does not name a confidential-computing scenario.
Who can reach it
Whoever controls the virtio-gpu device model on the host. Not reachable from inside the guest by a tenant, and not reachable over the network. No authentication concept applies — the backend is already the peer of the guest driver.
What to do
Patch the guest kernel to a stable release that also rejects reads whose end exceeds the edid array, then reboot the affected guests; conforming EDID responses are unaffected, so there is no functional regression to plan around. If a guest has no need for a virtio-gpu console, not attaching the device removes the exposure without a reboot cycle.
References
Related entries
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
- QEMU (virtio-net): Heap use-after-free in virtio_net_receive_rcu - guest-to-host code execution in the QEMU processCVE-2021-3748 · QEMU (virtio-net)High
- Linux kernel (drivers/nvme/target): When the target's peer-to-peer memory pool runs dry, it still tries to return theCVE-2021-47130 · Linux kernel (drivers/nvme/target)High
- QEMU (virtio-net): Map leaking on error during receive - guest-triggered host memory exhaustion / DoSCVE-2022-26353 · QEMU (virtio-net)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.