« Volver al listado

CVE-2026-64475

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

vfio/pci: Release the VGA arbiter client on register_device() failure

The re-order in the Fixes commit below displaced vfio_pci_vga_init() as the last failure point of what is now vfio_pci_core_register_device() without introducing an unwind for the VGA arbiter registration.

In current kernels this is mostly benign because vfio_pci_set_decode() only uses pci_dev state, but the original failure path could leave a callback with a freed vdev cookie. The stale registration also becomes unsafe again once the callback follows drvdata to the vfio device.

Leer descripción completaMostrar menos

Add the required VGA unwind callout.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) en kernel Linux sin interacción del usuario. Error de liberación de recursos en VGA arbiter podría permitir escalada de privilegios o lectura de memoria sensible tras fallo de registro.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64475",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "87856f9af04eaacf9848710625a4ffee1d020fa9",
              "lessThan": "0f2a35a0c7ea7da347b814750eaa78adf3582381",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "8d65decde9afd2bd78bcfffdc0df73b82a0b5509",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "ef4c38d30b3744e89eb5048218904bb629ea8d47",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "9e0a3f642e607848669235f5069f35640abbfc88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "42d758a09d2c46c42357ecde9a5492f015bde2e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "52adb2dff7ce3d8430e2bdc5988b618a430def85",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "278a5659c391fe5afe5f9ce1bad1fd24e90144f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4aeec3984ddc853f7c65903bde472ffdef738bae",
              "lessThan": "daedde7f024ecf88bc8e832ed40cf2c795f0796a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d62dccb417cf972c978bf3c68a7d5e846bcf953e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6694b8daffac5a8661071f085608afc78f7acd08",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.37",
              "lessThan": "5.10.261",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.11.21",
              "lessThan": "5.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.12.4",
              "lessThan": "5.13",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/vfio/pci/vfio_pci_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/vfio/pci/vfio_pci_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:32.980",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0f2a35a0c7ea7da347b814750eaa78adf3582381",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/278a5659c391fe5afe5f9ce1bad1fd24e90144f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/42d758a09d2c46c42357ecde9a5492f015bde2e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/52adb2dff7ce3d8430e2bdc5988b618a430def85",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d65decde9afd2bd78bcfffdc0df73b82a0b5509",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9e0a3f642e607848669235f5069f35640abbfc88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/daedde7f024ecf88bc8e832ed40cf2c795f0796a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef4c38d30b3744e89eb5048218904bb629ea8d47",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Release the VGA arbiter client on register_device() failure\n\nThe re-order in the Fixes commit below displaced vfio_pci_vga_init() as\nthe last failure point of what is now vfio_pci_core_register_device()\nwithout introducing an unwind for the VGA arbiter registration.\n\nIn current kernels this is mostly benign because vfio_pci_set_decode()\nonly uses pci_dev state, but the original failure path could leave a\ncallback with a freed vdev cookie.  The stale registration also becomes\nunsafe again once the callback follows drvdata to the vfio device.\n\nAdd the required VGA unwind callout."
    }
  ],
  "lastModified": "2026-08-17T05:17:53.140",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}