Database/Kernel, userspace & hypervisor
Linux vhost-scsi: stale response iovecs after a memory-table change write into unrelated memory
Impact
vhost-scsi translates guest response descriptors into host userspace iovecs at submission time, but target-core completes asynchronously. VHOST_SET_MEM_TABLE can swap the memory table while a command still holds iovecs translated through the old one, so the completion writes the SCSI response into an unrelated userspace object in the VMM process. The CVSS vector records a scope change - this crosses the VM boundary into the hypervisor process, which is exactly the boundary a GPU cloud sells. On nodes that pass GPUs into KVM guests with vhost-scsi storage, a guest that can drive the ioctl sequence gets a write into host VMM memory.
Who can reach it
Local - whoever controls the vhost-scsi device file and the ioctl sequence, i.e. the VMM process serving a guest, or a guest able to influence it. High attack complexity: the race between an in-flight command and the memory-table update has to be won. Only hosts using vhost-scsi are affected.
What to do
Install a kernel with the vhost-scsi backend-flush fix and reboot the hypervisor hosts; live migration of guests off the node first keeps the cost to a rolling drain. Hosts that do not use vhost-scsi storage for guests can defer.
References
Related entries
- Linux slab allocator: ABA race in the optimistic freelist return corrupts the partial listCVE-2026-97941 · Linux kernel mm/slab (__slab_try_return_freelist ABA race)High
- Linux AMD IOMMU: sign-discarding error check lets nested domains use an unallocated domain IDCVE-2026-98002 · Linux kernel iommu/amd (amd_iommu_alloc_domain_nested error check)High
- Linux kernel virtio-gpu: unvalidated EDID block offset lets a malicious backend read past a kernel bufferCVE-2026-68255 · Linux kernel drm/virtio (virtio_get_edid_block response bounds)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough): Buffer overflow on the MSI-X table write pathCVE-2015-8554 · Xen qemu-xen-traditional device model hw/pt-msi.c (MSI-X passthrough)High
- Linux kernel RDS net/rds/recv.c - rds_inc_info_copy: A structure member is left uninitialised before the RDS messageCVE-2016-5244 · Linux kernel RDS net/rds/recv.c - rds_inc_info_copyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.