Database/Kernel, userspace & hypervisor
Linux kernel vhost-vdpa: queue size is not checked against the device maximum, giving an out-of-bounds descriptor read
Impact
vhost_vring_set_num() accepts any non-zero power-of-two 16-bit queue size, and vhost-vdpa passed it straight to set_vq_num() without comparing it to get_vq_num_max(). A process that can open /dev/vhost-vdpa-* can therefore configure a virtqueue larger than the device advertises, and the worker then walks descriptors past the end of the mapped descriptor ring - KASAN reports a 16-byte out-of-bounds read of one vring_desc in the vringh IOTLB path. On a hypervisor host that hands vDPA devices to guests, this is host-side memory disclosure or a host crash driven from whoever holds the vhost-vdpa character device, which on a GPU virtualization node is the VM management stack rather than an ordinary tenant. Only relevant where vDPA is actually in use; hosts with no vhost-vdpa devices are unaffected.
Who can reach it
Local user or service with access to /dev/vhost-vdpa-* on the host (typically the VM/management layer, not a tenant). No remote path and no credentials beyond that device permission.
What to do
Update to a stable kernel containing the fix (the upstream change caches get_vq_num_max() after reset and validates the copied vring state before use) and reboot the node. On a GPU host that means draining tenant workloads first, so this lands in a normal kernel maintenance window. Interim mitigation: restrict permissions on /dev/vhost-vdpa-* to the VM management service only, or avoid vDPA devices on hosts that do not need them.
References
Related entries
- Linux kernel BPF verifier (bpf_loop nr_loops argument type): bpf_loop() declared nr_loops as ARG_ANYTHING, so aCVE-2026-98007 · Linux kernel BPF verifier (bpf_loop nr_loops argument type)Unscored
- Linux kernel BPF: bpf_btf_find_by_name_kind() can sleep in softirq context and install an fd into the interrupted taskCVE-2026-98046 · Linux kernel BPF helper bpf_btf_find_by_name_kind() (missing sleepable annotation)Unscored
- Linux kernel BPF: bpf_snprintf_btf() on a BTF_KIND_VAR from base BTF NULL-derefs in btf_var_show()CVE-2026-98063 · Linux kernel BPF BTF display (btf_var_show() unguarded resolved_ids deref)Unscored
- Linux kernel BPF: rendering a "const void" BTF type through bpf_snprintf_btf() NULL-derefs a missing show opCVE-2026-98064 · Linux kernel BPF BTF display (btf_modifier_show() missing show op for void)Unscored
- Linux kernel BPF: a key-less BTF hash map can be created and reading it through bpffs NULL-derefsCVE-2026-98065 · Linux kernel BPF hash maps (htab/rhtab map_check_btf key-less BTF)Unscored
- Linux kernel net/rds: a shutdown consuming a racing drop leaves an accepted socket wedged and never torn downCVE-2026-98068 · Linux kernel net/rds (rds_conn_shutdown() consuming a concurrent RDS_CONN_ERROR drop)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.