-

CVE-2026-97994

vhost/vdpa: reject VRING_NUM larger than device max

In the Linux kernel, the following vulnerability has been resolved:

vhost/vdpa: reject VRING_NUM larger than device max

vhost_vring_set_num() accepts any non-zero power-of-two queue size that
fits in 16 bits. vhost-vdpa then passes that value to set_vq_num()
without comparing it with get_vq_num_max().

A process with access to /dev/vhost-vdpa-* can therefore configure a
queue larger than the device advertises. With vdpa_sim, the worker can
walk descriptors beyond the mapped descriptor ring. KASAN reports a
16-byte out-of-bounds read, corresponding to one vring_desc, in the
vringh IOTLB path:

  BUG: KASAN: out-of-bounds in _copy_from_iter
  Read of size 16
  copy_from_iotlb
  copydesc_iotlb
  vringh_getdesc_iotlb
  vdpasim_net_work

Cache get_vq_num_max() immediately after reset. Some backends derive
it from writable queue-size state, so querying it after SET_NUM may
return the current size instead of the device capability. Invalidate
the cached value before reset so a failed reset leaves SET_NUM
disabled.

For VHOST_SET_VRING_NUM, copy the complete vring state once and use
the same index and size for validation, vq->num, and set_vq_num().
This ensures that validation and use operate on the same copied values.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4c8cf31885f69e86be0b5b9e6677a26797365e1d
Version < 4875c65ca53797a0a402fe2bb54d1b12f28b3cda
Status affected
Version 4c8cf31885f69e86be0b5b9e6677a26797365e1d
Version < 1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4
Status affected
Version 4c8cf31885f69e86be0b5b9e6677a26797365e1d
Version < 68232102f20fc961327fb9e0f605a7eaadf030a9
Status affected
Version 4c8cf31885f69e86be0b5b9e6677a26797365e1d
Version < 59522639a7d71cff4e20d594d0b9ea30dd0c77e0
Status affected
Version 4c8cf31885f69e86be0b5b9e6677a26797365e1d
Version < ccb1dc7c527f8c925925cf92afc76ae590dac311
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.7
Status affected
Version 0
Version < 5.7
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4
https://git.kernel.org/stable/c/68232102f20fc961327fb9e0f605a7eaadf030a9
https://git.kernel.org/stable/c/59522639a7d71cff4e20d594d0b9ea30dd0c77e0
https://git.kernel.org/stable/c/ccb1dc7c527f8c925925cf92afc76ae590dac311
https://git.kernel.org/stable/c/4875c65ca53797a0a402fe2bb54d1b12f28b3cda