Database/Kernel, userspace & hypervisor
Linux kernel vhost-vdpa: failed eventfd install leaves an ERR_PTR reachable by the config callback
Impact
vhost_vdpa_set_config_call() swapped the eventfd_ctx_fdget() result into v->config_ctx before checking it, so on failure the field briefly holds an ERR_PTR. The rest of the file only tests the pointer for NULL, so a config interrupt arriving inside that window hands the ERR_PTR straight to eventfd_signal() - a kernel-side bad-pointer dereference from a host process passing a bad fd. The same bug also tore down a working config interrupt: after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd. On a node using vDPA to present accelerated virtio devices to guests, that is a crash or a silently wedged device path driven from whatever component holds /dev/vhost-vdpa. No CVSS score or CWE is attached to the record.
Who can reach it
Local process with an open vhost-vdpa device - in practice the VMM (QEMU or similar) or a privileged management agent - calling VHOST_VDPA_SET_CONFIG_CALL with an invalid fd while the device delivers a config interrupt. Requires access to /dev/vhost-vdpa, not reachable from a guest or the network.
What to do
Update to a stable kernel where the fd is validated before being installed (matching how vhost_vring_ioctl() handles the same failure) and reboot the hosts running vDPA-backed virtio devices. The record lists stable commits only, with no fixed release numbers.
References
Related entries
- Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor readCVE-2026-97994 · Linux kernel vhost-vdpa (VHOST_SET_VRING_NUM validation)Unscored
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aCVE-2026-98007 · Linux kernel BPF verifier (bpf_loop nr_loops argument type)Unscored
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskCVE-2026-98046 · Linux kernel BPF helper bpf_btf_find_by_name_kind() (missing sleepable annotation)Unscored
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.