« Volver al listado

CVE-2026-93782

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

vhost-scsi: flush backend after device ioctls

vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through the old table.

If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command completion can write the response to an unrelated userspace object.

Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device ioctl. This waits for in-flight commands that can still use the old response iovecs before the ioctl returns.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de escalada local (AV:L, PR:L) en vhost-scsi: VHOST_SET_MEM_TABLE reemplaza tabla de memoria mientras comandos en vuelo usan iovecs antiguos, permitiendo escritura en memoria no relacionada (corrupción de datos).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93782",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.1
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "6436411203d8c702ffc055700f1a6bde488ff681",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "cec088285adcc7ae23c119b6bbdb22270dc2de8f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "e0bf6bed528693a6b32439ab122b34a34b66d96f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "be2636e1b21fe860db918152abf2932638d06ed7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "981c97d09c6b9560bb12dcc41f11ce59b1a48e97",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "6c1b802e36b05ebd9d41686c4dce6f06966af469",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "057cbf49a1f08297877e46c82f707b1bfea806a8",
              "lessThan": "22598f55a4c2b510b3df5e69e563387a963222ae",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/vhost/scsi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/vhost/scsi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:10.793",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/22598f55a4c2b510b3df5e69e563387a963222ae",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6436411203d8c702ffc055700f1a6bde488ff681",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c1b802e36b05ebd9d41686c4dce6f06966af469",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/981c97d09c6b9560bb12dcc41f11ce59b1a48e97",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be2636e1b21fe860db918152abf2932638d06ed7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cec088285adcc7ae23c119b6bbdb22270dc2de8f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0bf6bed528693a6b32439ab122b34a34b66d96f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: flush backend after device ioctls\n\nvhost-scsi translates guest response descriptors into userspace iovecs\nwhen commands are submitted.  Target-core completes those commands\nasynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while\nan in-flight command still retains response iovecs translated through the\nold table.\n\nIf the old mapping is reused after VHOST_SET_MEM_TABLE returns, command\ncompletion can write the response to an unrelated userspace object.\n\nFlush the vhost-scsi backend after vhost_dev_ioctl() handles a device\nioctl.  This waits for in-flight commands that can still use the old\nresponse iovecs before the ioctl returns."
    }
  ],
  "lastModified": "2026-10-03T11:17:47.667",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}