« Volver al listado

CVE-2026-97989

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

vduse: validate virtqueue alignment

vduse_validate_config() only checks the upper bound of vq_align. Invalid values can therefore reach vring_create_virtqueue_map(). The split-ring helpers use align - 1 as a bit mask, so the alignment must be a non-zero power of two. A zero value makes vring_size() drop the descriptor and available-ring part and vring_init() leave the used ring pointer NULL.

The VIRTIO spec requires the used ring to start at an address aligned to at least 4 bytes. Reject values below VRING_USED_ALIGN_SIZE as well as non-power-of-two values before they reach the virtio ring helpers.

Leer descripción completaMostrar menos

Opening a virtio-net device created with vq_align=0 triggered:

Validate the value before it reaches the virtio ring helpers.

Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: null-ptr-deref in virtqueue_kick_prepare_split+0xe3/0x100
Read of size 2 at addr 0000000000000000 by task systemd-network/1062

Call Trace (relevant frames):
 dump_stack_lvl
 print_report
 kasan_report
 __asan_load2
 virtqueue_kick_prepare_split+0xe3/0x100
 virtqueue_kick_prepare+0x40/0x60
 try_fill_recv+0x857/0x1250
 virtnet_open+0x189/0x460
 __dev_open+0x225/0x390
 __dev_change_flags+0x368/0x3b0
 netif_change_flags+0x56/0xc0
 do_setlink.isra.0+0x68c/0x1e30

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97989",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c8a6153b6c59d95c0e091f053f6f180952ade91e",
              "lessThan": "c3c3b0839a1197530cc18f535062fc84dbdfc885",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c8a6153b6c59d95c0e091f053f6f180952ade91e",
              "lessThan": "fa2c25b4add57888acfa89e398389e267bff3dcf",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/vdpa/vdpa_user/vduse_dev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/vdpa/vdpa_user/vduse_dev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:27.010",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/c3c3b0839a1197530cc18f535062fc84dbdfc885",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fa2c25b4add57888acfa89e398389e267bff3dcf",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvduse: validate virtqueue alignment\n\nvduse_validate_config() only checks the upper bound of vq_align. Invalid\nvalues can therefore reach vring_create_virtqueue_map(). The split-ring\nhelpers use align - 1 as a bit mask, so the alignment must be a non-zero\npower of two. A zero value makes vring_size() drop the descriptor and\navailable-ring part and vring_init() leave the used ring pointer NULL.\n\nThe VIRTIO spec requires the used ring to start at an address\naligned to at least 4 bytes. Reject values below VRING_USED_ALIGN_SIZE as\nwell as non-power-of-two values before they reach the virtio ring helpers.\n\nOpening a virtio-net device created with vq_align=0 triggered:\n\nBUG: KASAN: null-ptr-deref in virtqueue_kick_prepare_split+0xe3/0x100\nRead of size 2 at addr 0000000000000000 by task systemd-network/1062\n\nCall Trace (relevant frames):\n dump_stack_lvl\n print_report\n kasan_report\n __asan_load2\n virtqueue_kick_prepare_split+0xe3/0x100\n virtqueue_kick_prepare+0x40/0x60\n try_fill_recv+0x857/0x1250\n virtnet_open+0x189/0x460\n __dev_open+0x225/0x390\n __dev_change_flags+0x368/0x3b0\n netif_change_flags+0x56/0xc0\n do_setlink.isra.0+0x68c/0x1e30\n\nValidate the value before it reaches the virtio ring helpers."
    }
  ],
  "lastModified": "2026-09-25T11:17:27.010",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}