CVE-2026-97478
In the Linux kernel, the following vulnerability has been resolved:
virt: acrn: Fix irqfd use-after-free during eventfd shutdown
acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free the same struct hsm_irqfd:
The deassign path freed the irqfd while a shutdown work item was already queued by EPOLLHUP (or vice versa), so the work item could resurrect a dangling pointer through container_of().
Switch to the lifetime model used by KVM irqfds:
Detalles técnicos trazas, registros y código del informe original
CPU0 CPU1
---- ----
eventfd_release()
wake_up_poll(EPOLLHUP)
hsm_irqfd_wakeup()
queue_work(&irqfd->shutdown)
acrn_irqfd_deassign()
hsm_irqfd_shutdown()
list_del_init()
eventfd_ctx_remove_wait_queue()
eventfd_ctx_put()
kfree(irqfd)
hsm_irqfd_shutdown_work()
container_of(work, ..., shutdown)
irqfd->vm <-- use-after-free
- Deassign/deinit only deactivate the irqfd: remove it from vm->irqfds
under irqfds_lock and queue the cleanup work.
- hsm_irqfd_shutdown_work() becomes the sole owner that unhooks the
eventfd waitqueue entry, drops the eventfd reference and frees the
irqfd.
- A new HSM_IRQFD_FLAG_SHUTDOWN bit guarded by test_and_set_bit()
ensures the cleanup work is queued at most once, no matter how many
of {EPOLLHUP, deassign, deinit} fire concurrently. This is safe to
call from the waitqueue callback, which runs with wqh->lock held and
IRQs disabled and therefore cannot take irqfds_lock.
- acrn_irqfd_deassign() flushes vm->irqfd_wq before returning so the
eventfd is fully detached on return. acrn_irqfd_deinit() deactivates
every irqfd, flushes the workqueue and only then destroys it, so no
path can queue_work() onto a torn-down workqueue.
- acrn_irqfd_assign() now installs the eventfd waitqueue entry and
publishes the irqfd to vm->irqfds under irqfds_lock, so the irqfd is
never visible to deassign/deinit before its waitqueue entry is in
place, and any EPOLLHUP that fires in the assign window queues
cleanup work that blocks on irqfds_lock until publication is done.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation90 % - Impacto principal
T1499.004Application or System Exploitationimpact75 %
Use-after-free en kernel de Linux (AV:L, PR:L) permite escalada de privilegios (T1068). El fallo de sincronización causa DoS por corrupción de memoria (T1499.004).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97478",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "aa3b483ff1d71c50b33db154048dff9a8f08ac71",
"lessThan": "d8156aacfcabb81f52c20ef89094945434d08079",
"versionType": "git"
},
{
"status": "affected",
"version": "aa3b483ff1d71c50b33db154048dff9a8f08ac71",
"lessThan": "666c7f9e07925aa0863348f960e09bb89f8f05a3",
"versionType": "git"
}
],
"programFiles": [
"drivers/virt/acrn/irqfd.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/virt/acrn/irqfd.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:25.183",
"references": [
{
"url": "https://git.kernel.org/stable/c/666c7f9e07925aa0863348f960e09bb89f8f05a3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d8156aacfcabb81f52c20ef89094945434d08079",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirt: acrn: Fix irqfd use-after-free during eventfd shutdown\n\nacrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free\nthe same struct hsm_irqfd:\n\n CPU0 CPU1\n ---- ----\n eventfd_release()\n wake_up_poll(EPOLLHUP)\n hsm_irqfd_wakeup()\n queue_work(&irqfd->shutdown)\n acrn_irqfd_deassign()\n hsm_irqfd_shutdown()\n list_del_init()\n eventfd_ctx_remove_wait_queue()\n eventfd_ctx_put()\n kfree(irqfd)\n hsm_irqfd_shutdown_work()\n container_of(work, ..., shutdown)\n irqfd->vm <-- use-after-free\n\nThe deassign path freed the irqfd while a shutdown work item was\nalready queued by EPOLLHUP (or vice versa), so the work item could\nresurrect a dangling pointer through container_of().\n\nSwitch to the lifetime model used by KVM irqfds:\n\n - Deassign/deinit only deactivate the irqfd: remove it from vm->irqfds\n under irqfds_lock and queue the cleanup work.\n - hsm_irqfd_shutdown_work() becomes the sole owner that unhooks the\n eventfd waitqueue entry, drops the eventfd reference and frees the\n irqfd.\n - A new HSM_IRQFD_FLAG_SHUTDOWN bit guarded by test_and_set_bit()\n ensures the cleanup work is queued at most once, no matter how many\n of {EPOLLHUP, deassign, deinit} fire concurrently. This is safe to\n call from the waitqueue callback, which runs with wqh->lock held and\n IRQs disabled and therefore cannot take irqfds_lock.\n - acrn_irqfd_deassign() flushes vm->irqfd_wq before returning so the\n eventfd is fully detached on return. acrn_irqfd_deinit() deactivates\n every irqfd, flushes the workqueue and only then destroys it, so no\n path can queue_work() onto a torn-down workqueue.\n - acrn_irqfd_assign() now installs the eventfd waitqueue entry and\n publishes the irqfd to vm->irqfds under irqfds_lock, so the irqfd is\n never visible to deassign/deinit before its waitqueue entry is in\n place, and any EPOLLHUP that fires in the assign window queues\n cleanup work that blocks on irqfds_lock until publication is done."
}
],
"lastModified": "2026-09-28T06:16:33.703",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}