GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel virtio-fs: double free of fs->vqs and fs->mq_map when queue setup fails during probe

CVSS 8.4CVE-2026-93827Kernel, userspace & hypervisorcurated

Impact

virtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling virtio_find_vqs(). When that call fails, the error path frees both and returns to virtio_fs_probe(), which drops the last kobject reference; virtio_fs_ktype_release() then frees the same two pointers again. The fix nulls them after kfree() so the later release is a harmless kfree(NULL). Reaching it requires a virtio-fs device that advertises more request queues than the transport actually provides, so the exposure is a malicious or broken host-side device description hitting a guest at probe time - relevant where GPU workloads run in VMs and use virtio-fs to reach shared model or dataset storage. A guest-side attacker with no control over the virtio device cannot trigger it, and hosts that do not present virtio-fs to guests are unaffected. NVD scores it 8.4 local; treat it as a probe-time memory-corruption bug in the guest, not a remotely reachable one.

Who can reach it

Requires control of the virtio-fs device presented to the guest - a hostile or misconfigured hypervisor/vhost-user daemon - or a device-emulation bug. Triggered once, during guest device probe. Not reachable by an unprivileged process inside the guest, and not reachable at all on nodes without virtio-fs.

What to do

Pick up the stable kernel containing the fix (commits linked in the record) and reboot the affected guests; virtio-fs is built in or loaded early, so there is no live-patch or module-reload path in practice. On a GPU fleet this is guest-VM maintenance rather than host maintenance unless your hosts are themselves virtio-fs guests. If you do not expose virtio-fs to guests, this can wait for your normal kernel cycle.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.