CVE-2026-97990
In the Linux kernel, the following vulnerability has been resolved:
vdpa_sim_net: check TX pull result before RX copy
vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is currently added to the unsigned byte counter and then passed as a size_t length to receive_filter() and vringh_iov_push_iotlb(). A negative error can therefore become a large length in the RX path.
Handle non-positive pull results before every length use. Count the TX error and complete the consumed TX descriptor with zero bytes.
I found this bug myself, though the patch was written with AI assistance.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 % - Impacto secundario
T1565.001Stored Data Manipulationimpact55 %
Vulnerabilidad de kernel Linux con AV:L y PR:L permite escalada local (T1068). El desbordamiento de buffer causado por valor negativo interpretado como tamaño grande causa DoS (negación de servicio) e integridad de datos en la RX.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0d195797a80b77f2ec56718cd26d3ee65d0093e8
- https://git.kernel.org/stable/c/1b803d382cde6d85755b363f22010208a04ba40a
- https://git.kernel.org/stable/c/2bbf1c1f69991e28787e02b0a2f826289d5fc730
- https://git.kernel.org/stable/c/3af20238a09ca180d66623e3bed16b64e9975f39
- https://git.kernel.org/stable/c/c001abcde865b74231da8f1412c3217dbf66781e
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97990",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.8,
"exploitabilityScore": 1.1
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "cfe226892913a448e83e7a19db93862baa3cb99c",
"lessThan": "1b803d382cde6d85755b363f22010208a04ba40a",
"versionType": "git"
},
{
"status": "affected",
"version": "cfe226892913a448e83e7a19db93862baa3cb99c",
"lessThan": "c001abcde865b74231da8f1412c3217dbf66781e",
"versionType": "git"
},
{
"status": "affected",
"version": "cfe226892913a448e83e7a19db93862baa3cb99c",
"lessThan": "3af20238a09ca180d66623e3bed16b64e9975f39",
"versionType": "git"
},
{
"status": "affected",
"version": "cfe226892913a448e83e7a19db93862baa3cb99c",
"lessThan": "2bbf1c1f69991e28787e02b0a2f826289d5fc730",
"versionType": "git"
},
{
"status": "affected",
"version": "cfe226892913a448e83e7a19db93862baa3cb99c",
"lessThan": "0d195797a80b77f2ec56718cd26d3ee65d0093e8",
"versionType": "git"
}
],
"programFiles": [
"drivers/vdpa/vdpa_sim/vdpa_sim_net.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/vdpa/vdpa_sim/vdpa_sim_net.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:27.113",
"references": [
{
"url": "https://git.kernel.org/stable/c/0d195797a80b77f2ec56718cd26d3ee65d0093e8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1b803d382cde6d85755b363f22010208a04ba40a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2bbf1c1f69991e28787e02b0a2f826289d5fc730",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3af20238a09ca180d66623e3bed16b64e9975f39",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c001abcde865b74231da8f1412c3217dbf66781e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa_sim_net: check TX pull result before RX copy\n\nvringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is\ncurrently added to the unsigned byte counter and then passed as a size_t\nlength to receive_filter() and vringh_iov_push_iotlb(). A negative error\ncan therefore become a large length in the RX path.\n\nHandle non-positive pull results before every length use. Count the TX\nerror and complete the consumed TX descriptor with zero bytes.\n\nI found this bug myself, though the patch was written with AI assistance."
}
],
"lastModified": "2026-10-03T11:18:22.720",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}