« Volver al listado

CVE-2026-97990

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

vdpa_sim_net: check TX pull result before RX copy

vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is currently added to the unsigned byte counter and then passed as a size_t length to receive_filter() and vringh_iov_push_iotlb(). A negative error can therefore become a large length in the RX path.

Handle non-positive pull results before every length use. Count the TX error and complete the consumed TX descriptor with zero bytes.

I found this bug myself, though the patch was written with AI assistance.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de kernel Linux con AV:L y PR:L permite escalada local (T1068). El desbordamiento de buffer causado por valor negativo interpretado como tamaño grande causa DoS (negación de servicio) e integridad de datos en la RX.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97990",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.1
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "cfe226892913a448e83e7a19db93862baa3cb99c",
              "lessThan": "1b803d382cde6d85755b363f22010208a04ba40a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cfe226892913a448e83e7a19db93862baa3cb99c",
              "lessThan": "c001abcde865b74231da8f1412c3217dbf66781e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cfe226892913a448e83e7a19db93862baa3cb99c",
              "lessThan": "3af20238a09ca180d66623e3bed16b64e9975f39",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cfe226892913a448e83e7a19db93862baa3cb99c",
              "lessThan": "2bbf1c1f69991e28787e02b0a2f826289d5fc730",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cfe226892913a448e83e7a19db93862baa3cb99c",
              "lessThan": "0d195797a80b77f2ec56718cd26d3ee65d0093e8",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/vdpa/vdpa_sim/vdpa_sim_net.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/vdpa/vdpa_sim/vdpa_sim_net.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:27.113",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0d195797a80b77f2ec56718cd26d3ee65d0093e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1b803d382cde6d85755b363f22010208a04ba40a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2bbf1c1f69991e28787e02b0a2f826289d5fc730",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3af20238a09ca180d66623e3bed16b64e9975f39",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c001abcde865b74231da8f1412c3217dbf66781e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa_sim_net: check TX pull result before RX copy\n\nvringh_iov_pull_iotlb() returns a signed byte count.  A failed TX pull is\ncurrently added to the unsigned byte counter and then passed as a size_t\nlength to receive_filter() and vringh_iov_push_iotlb().  A negative error\ncan therefore become a large length in the RX path.\n\nHandle non-positive pull results before every length use.  Count the TX\nerror and complete the consumed TX descriptor with zero bytes.\n\nI found this bug myself, though the patch was written with AI assistance."
    }
  ],
  "lastModified": "2026-10-03T11:18:22.720",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}