8.4

CVE-2026-93827

virtio-fs: avoid double-free on failed queue setup

In the Linux kernel, the following vulnerability has been resolved:

virtio-fs: avoid double-free on failed queue setup

virtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling
virtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both
pointers and returns an error to virtio_fs_probe().

virtio_fs_probe() then drops the last kobject reference, and
virtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves
dangling pointers in struct virtio_fs and can trigger a double-free during
probe failure cleanup.

Set fs->vqs and fs->mq_map to NULL immediately after kfree() in the
virtio_fs_setup_vqs() error path so that the later kobject release sees an
uninitialized state and kfree(NULL) becomes harmless.

This can be reproduced when a broken virtio-fs device advertises more
request queues than the transport actually provides. In that case
virtio_find_vqs() fails while setting up the extra queue, and the probe
path reaches the double-free cleanup sequence.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9
Version < 3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad
Status affected
Version a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9
Version < 20ef4739b329bb09cff11dd2458795a50674658e
Status affected
Version a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9
Version < 6af3330ec5d5fb8c06c04eb520a71cf73ea5a765
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.9
Status affected
Version 0
Version < 6.9
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad
https://git.kernel.org/stable/c/20ef4739b329bb09cff11dd2458795a50674658e
https://git.kernel.org/stable/c/6af3330ec5d5fb8c06c04eb520a71cf73ea5a765