GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callback

UnscoredCVE-2026-97993Kernel, userspace & hypervisorcurated

Impact

vhost_vdpa_set_config_call() swapped the eventfd_ctx_fdget() result into v->config_ctx before checking it, so on failure the field briefly holds an ERR_PTR. The rest of the file only tests the pointer for NULL, so a config interrupt arriving inside that window hands the ERR_PTR straight to eventfd_signal() - a kernel-side bad-pointer dereference from a host process passing a bad fd. The same bug also tore down a working config interrupt: after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd. On a node using vDPA to present accelerated virtio devices to guests, that is a crash or a silently wedged device path driven from whatever component holds /dev/vhost-vdpa. No CVSS score or CWE is attached to the record.

Who can reach it

Local process with an open vhost-vdpa device - in practice the VMM (QEMU or similar) or a privileged management agent - calling VHOST_VDPA_SET_CONFIG_CALL with an invalid fd while the device delivers a config interrupt. Requires access to /dev/vhost-vdpa, not reachable from a guest or the network.

What to do

Update to a stable kernel where the fd is validated before being installed (matching how vhost_vring_ioctl() handles the same failure) and reboot the hosts running vDPA-backed virtio devices. The record lists stable commits only, with no fixed release numbers.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.