CVE-2026-97994
In the Linux kernel, the following vulnerability has been resolved:
vhost/vdpa: reject VRING_NUM larger than device max
vhost_vring_set_num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to set_vq_num() without comparing it with get_vq_num_max().
A process with access to /dev/vhost-vdpa-* can therefore configure a queue larger than the device advertises. With vdpa_sim, the worker can walk descriptors beyond the mapped descriptor ring. KASAN reports a 16-byte out-of-bounds read, corresponding to one vring_desc, in the vringh IOTLB path:
Cache get_vq_num_max() immediately after reset. Some backends derive it from writable queue-size state, so querying it after SET_NUM may return the current size instead of the device capability.
Leer descripción completaMostrar menos
Invalidate the cached value before reset so a failed reset leaves SET_NUM disabled.
For VHOST_SET_VRING_NUM, copy the complete vring state once and use the same index and size for validation, vq->num, and set_vq_num(). This ensures that validation and use operate on the same copied values.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: out-of-bounds in _copy_from_iter Read of size 16 copy_from_iotlb copydesc_iotlb vringh_getdesc_iotlb vdpasim_net_work
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4
- https://git.kernel.org/stable/c/4875c65ca53797a0a402fe2bb54d1b12f28b3cda
- https://git.kernel.org/stable/c/59522639a7d71cff4e20d594d0b9ea30dd0c77e0
- https://git.kernel.org/stable/c/68232102f20fc961327fb9e0f605a7eaadf030a9
- https://git.kernel.org/stable/c/ccb1dc7c527f8c925925cf92afc76ae590dac311
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97994",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4c8cf31885f69e86be0b5b9e6677a26797365e1d",
"lessThan": "4875c65ca53797a0a402fe2bb54d1b12f28b3cda",
"versionType": "git"
},
{
"status": "affected",
"version": "4c8cf31885f69e86be0b5b9e6677a26797365e1d",
"lessThan": "1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4",
"versionType": "git"
},
{
"status": "affected",
"version": "4c8cf31885f69e86be0b5b9e6677a26797365e1d",
"lessThan": "68232102f20fc961327fb9e0f605a7eaadf030a9",
"versionType": "git"
},
{
"status": "affected",
"version": "4c8cf31885f69e86be0b5b9e6677a26797365e1d",
"lessThan": "59522639a7d71cff4e20d594d0b9ea30dd0c77e0",
"versionType": "git"
},
{
"status": "affected",
"version": "4c8cf31885f69e86be0b5b9e6677a26797365e1d",
"lessThan": "ccb1dc7c527f8c925925cf92afc76ae590dac311",
"versionType": "git"
}
],
"programFiles": [
"drivers/vhost/vdpa.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/vhost/vdpa.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:27.637",
"references": [
{
"url": "https://git.kernel.org/stable/c/1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4875c65ca53797a0a402fe2bb54d1b12f28b3cda",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/59522639a7d71cff4e20d594d0b9ea30dd0c77e0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/68232102f20fc961327fb9e0f605a7eaadf030a9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ccb1dc7c527f8c925925cf92afc76ae590dac311",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/vdpa: reject VRING_NUM larger than device max\n\nvhost_vring_set_num() accepts any non-zero power-of-two queue size that\nfits in 16 bits. vhost-vdpa then passes that value to set_vq_num()\nwithout comparing it with get_vq_num_max().\n\nA process with access to /dev/vhost-vdpa-* can therefore configure a\nqueue larger than the device advertises. With vdpa_sim, the worker can\nwalk descriptors beyond the mapped descriptor ring. KASAN reports a\n16-byte out-of-bounds read, corresponding to one vring_desc, in the\nvringh IOTLB path:\n\n BUG: KASAN: out-of-bounds in _copy_from_iter\n Read of size 16\n copy_from_iotlb\n copydesc_iotlb\n vringh_getdesc_iotlb\n vdpasim_net_work\n\nCache get_vq_num_max() immediately after reset. Some backends derive\nit from writable queue-size state, so querying it after SET_NUM may\nreturn the current size instead of the device capability. Invalidate\nthe cached value before reset so a failed reset leaves SET_NUM\ndisabled.\n\nFor VHOST_SET_VRING_NUM, copy the complete vring state once and use\nthe same index and size for validation, vq->num, and set_vq_num().\nThis ensures that validation and use operate on the same copied values."
}
],
"lastModified": "2026-10-03T11:18:23.120",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}