7.5

CVE-2026-97990

vdpa_sim_net: check TX pull result before RX copy

In the Linux kernel, the following vulnerability has been resolved:

vdpa_sim_net: check TX pull result before RX copy

vringh_iov_pull_iotlb() returns a signed byte count.  A failed TX pull is
currently added to the unsigned byte counter and then passed as a size_t
length to receive_filter() and vringh_iov_push_iotlb().  A negative error
can therefore become a large length in the RX path.

Handle non-positive pull results before every length use.  Count the TX
error and complete the consumed TX descriptor with zero bytes.

I found this bug myself, though the patch was written with AI assistance.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version cfe226892913a448e83e7a19db93862baa3cb99c
Version < 1b803d382cde6d85755b363f22010208a04ba40a
Status affected
Version cfe226892913a448e83e7a19db93862baa3cb99c
Version < c001abcde865b74231da8f1412c3217dbf66781e
Status affected
Version cfe226892913a448e83e7a19db93862baa3cb99c
Version < 3af20238a09ca180d66623e3bed16b64e9975f39
Status affected
Version cfe226892913a448e83e7a19db93862baa3cb99c
Version < 2bbf1c1f69991e28787e02b0a2f826289d5fc730
Status affected
Version cfe226892913a448e83e7a19db93862baa3cb99c
Version < 0d195797a80b77f2ec56718cd26d3ee65d0093e8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.19
Status affected
Version 0
Version < 5.19
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.015
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 1.1 5.8
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c001abcde865b74231da8f1412c3217dbf66781e
https://git.kernel.org/stable/c/3af20238a09ca180d66623e3bed16b64e9975f39
https://git.kernel.org/stable/c/2bbf1c1f69991e28787e02b0a2f826289d5fc730
https://git.kernel.org/stable/c/0d195797a80b77f2ec56718cd26d3ee65d0093e8
https://git.kernel.org/stable/c/1b803d382cde6d85755b363f22010208a04ba40a