7.8

CVE-2026-93782

vhost-scsi: flush backend after device ioctls

In the Linux kernel, the following vulnerability has been resolved:

vhost-scsi: flush backend after device ioctls

vhost-scsi translates guest response descriptors into userspace iovecs
when commands are submitted.  Target-core completes those commands
asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while
an in-flight command still retains response iovecs translated through the
old table.

If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command
completion can write the response to an unrelated userspace object.

Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device
ioctl.  This waits for in-flight commands that can still use the old
response iovecs before the ioctl returns.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < 6436411203d8c702ffc055700f1a6bde488ff681
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < cec088285adcc7ae23c119b6bbdb22270dc2de8f
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < e0bf6bed528693a6b32439ab122b34a34b66d96f
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < be2636e1b21fe860db918152abf2932638d06ed7
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < 981c97d09c6b9560bb12dcc41f11ce59b1a48e97
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < 6c1b802e36b05ebd9d41686c4dce6f06966af469
Status affected
Version 057cbf49a1f08297877e46c82f707b1bfea806a8
Version < 22598f55a4c2b510b3df5e69e563387a963222ae
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.6
Status affected
Version 0
Version < 3.6
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.016
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/981c97d09c6b9560bb12dcc41f11ce59b1a48e97
https://git.kernel.org/stable/c/6c1b802e36b05ebd9d41686c4dce6f06966af469
https://git.kernel.org/stable/c/22598f55a4c2b510b3df5e69e563387a963222ae
https://git.kernel.org/stable/c/6436411203d8c702ffc055700f1a6bde488ff681
https://git.kernel.org/stable/c/be2636e1b21fe860db918152abf2932638d06ed7
https://git.kernel.org/stable/c/cec088285adcc7ae23c119b6bbdb22270dc2de8f
https://git.kernel.org/stable/c/e0bf6bed528693a6b32439ab122b34a34b66d96f