-

CVE-2026-90129

virtio_balloon: quiesce balloon work before device shutdown

In the Linux kernel, the following vulnerability has been resolved:

virtio_balloon: quiesce balloon work before device shutdown

Commit 8bd2fa086a04 ("virtio: break and reset virtio devices on
device_shutdown()") added a generic virtio bus .shutdown handler that
breaks and resets every virtio device during device_shutdown(), i.e. on
reboot and kexec.

virtio_balloon provides no .shutdown of its own, so that generic path
runs while the balloon's asynchronous work is still armed. Once the
device has been broken, virtqueue_add_inbuf() in
virtballoon_free_page_report() returns -EIO and trips its
WARN_ON_ONCE(). On a kernel booted with panic_on_warn that turns an
ordinary reboot, for example a kexec based upgrade, into a fatal panic
in the middle of device_shutdown(), so the machine never reaches the
new kernel.

Relaxing that single WARN_ON_ONCE() would only hide the symptom: the
inflate/deflate and OOM paths do not warn, they call
wait_event(vb->acked, ...) and would instead block forever on a broken
queue that can no longer complete. The device has to be quiesced, not
just kept quiet.

Add a .shutdown handler that quiesces the balloon via the shared
virtballoon_quiesce() helper while the device is still alive, and only
then breaks and resets it via virtio_device_shutdown(). Unlike
virtballoon_remove() the balloon workqueue is not destroyed, as shutdown
does not free the device and cancel_work_sync() together with stop_update
already prevent any further work from being queued.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8bd2fa086a04886798b505f28db4002525895203
Version < 6dd28e32f4d81a0d57c732b9900de24184e60a7d
Status affected
Version 8bd2fa086a04886798b505f28db4002525895203
Version < bdef50a8226fc04899ef6815dd08a002247d47d5
Status affected
Version 8bd2fa086a04886798b505f28db4002525895203
Version < 7e17eef04600c399c7e0f5ce765da5cf9d40d8e1
Status affected
Version aee42f3d57bfa37b2716df4584edeecf63b9df4c
Status affected
Version 6.14.9
Version < 6.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/6dd28e32f4d81a0d57c732b9900de24184e60a7d
https://git.kernel.org/stable/c/bdef50a8226fc04899ef6815dd08a002247d47d5
https://git.kernel.org/stable/c/7e17eef04600c399c7e0f5ce765da5cf9d40d8e1