-

CVE-2026-72138

xen/gntdev: fix error handling in ioctl

In the Linux kernel, the following vulnerability has been resolved:

xen/gntdev: fix error handling in ioctl

When gntdev_ioctl_map_grant_ref() fails to copy the operation result
back to userspace after successfully adding the mapping to the list,
the error path returns -EFAULT without releasing the reference
acquired by gntdev_alloc_map(). The mapping remains in priv->maps
with a refcount of 1, causing a memory leak and a dangling list
entry.

Additionally, gntdev_add_map() may modify map->index to avoid overlap
with existing mappings. Therefore, the index returned to userspace
must be obtained after gntdev_add_map() completes.

Fix this by holding the mutex across gntdev_add_map(), retrieving
the correct index, and copy_to_user(). If copy_to_user() fails,
remove the mapping from the list and release the reference while
still holding the lock.


Fix these issues by properly handling all error cases.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 52dc40ef0cfee6ae89b7524967e73f0ba37906d7
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 1dd9cb98fe228e017fff9efb33862ff38c741b65
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 6df926130aee6cab9b5d2e5b7862e49ccac348dc
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 311011f8cc206c5af2877b03e3f627ee1b8fe024
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 18a693733f7ad004e1ab0466693121ca70cd95dd
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 6883269a323609f68f6faa903f8f8ff3d191cec8
Status affected
Version 68b025c813c2eb41ff25628e3d4952d5185eb1a4
Version < 45ca1afe2fd14c04e37227e79d3f8455831d8408
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.39
Status affected
Version 0
Version < 2.6.39
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.115
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/52dc40ef0cfee6ae89b7524967e73f0ba37906d7
https://git.kernel.org/stable/c/1dd9cb98fe228e017fff9efb33862ff38c741b65
https://git.kernel.org/stable/c/6df926130aee6cab9b5d2e5b7862e49ccac348dc
https://git.kernel.org/stable/c/311011f8cc206c5af2877b03e3f627ee1b8fe024
https://git.kernel.org/stable/c/18a693733f7ad004e1ab0466693121ca70cd95dd
https://git.kernel.org/stable/c/16d3ccdabb8dee9be2cdcd6d3f9a125572ec0454
https://git.kernel.org/stable/c/6883269a323609f68f6faa903f8f8ff3d191cec8
https://git.kernel.org/stable/c/45ca1afe2fd14c04e37227e79d3f8455831d8408