CVE-2026-97995
In the Linux kernel, the following vulnerability has been resolved:
virtio_console: do not free control-out buffers on remove
__send_control_msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover cookies to free_buf(), which treats them as struct port_buffer and reads sgpages.
If a control message is still on c_ovq when the device is unbound, free_buf() reads past the ports_device object.
The object was the ports_device allocated in virtcons_probe().
Drain c_ovq without freeing. The packet lives in portdev and is released with it.
Detalles técnicos trazas, registros y código del informe original
KASAN reported slab-out-of-bounds in free_buf(): free_buf remove_vqs virtcons_remove unbind_store
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/177ee901aa2bab02e7f1f8edbb814fd5e386ed62
- https://git.kernel.org/stable/c/2e40c69b9c3448b9c6609cd02013da593b2e123b
- https://git.kernel.org/stable/c/894f98e73983f37354214a89a3a7fd35bf9e3072
- https://git.kernel.org/stable/c/8f6cfc3eca79b8e108d0823756101e2f4f9d811f
- https://git.kernel.org/stable/c/a80c33488e0bbe642ed803b13a4ac8078a70b507
- https://git.kernel.org/stable/c/b1f39c2a676698cc64c8e105e08b25111a112ec6
- https://git.kernel.org/stable/c/e03522a990cd2e0f1a736eaa349a9df9ab8541c3
- https://git.kernel.org/stable/c/f620c40ea6862feed84deb105568b21ec53a7830
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97995",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "b1f39c2a676698cc64c8e105e08b25111a112ec6",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "e03522a990cd2e0f1a736eaa349a9df9ab8541c3",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "8f6cfc3eca79b8e108d0823756101e2f4f9d811f",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "2e40c69b9c3448b9c6609cd02013da593b2e123b",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "177ee901aa2bab02e7f1f8edbb814fd5e386ed62",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "a80c33488e0bbe642ed803b13a4ac8078a70b507",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "f620c40ea6862feed84deb105568b21ec53a7830",
"versionType": "git"
},
{
"status": "affected",
"version": "a7a69ec0d8e4a58be7db88d33cbfa2912807bb2b",
"lessThan": "894f98e73983f37354214a89a3a7fd35bf9e3072",
"versionType": "git"
},
{
"status": "affected",
"version": "f92b16b815efe8207090a9b5a767618fd89542ca",
"versionType": "git"
},
{
"status": "affected",
"version": "d2bbfac82b7942afc5d8e564d7087835280df495",
"versionType": "git"
},
{
"status": "affected",
"version": "a88e13d9a092fbb772d380944b44eb549ef131fe",
"versionType": "git"
},
{
"status": "affected",
"version": "dd807a784fd36f4136516d5858efb6473dda422c",
"versionType": "git"
},
{
"status": "affected",
"version": "47cb14192bcbba3f15b1c3561e05e084e56fdef6",
"versionType": "git"
},
{
"status": "affected",
"version": "6b1c41a0f7183702abb7a104c6c7e196ad69a6b3",
"versionType": "git"
},
{
"status": "affected",
"version": "9037306163a6ba5587e4b5ca511ac7be4fb7295b",
"versionType": "git"
},
{
"status": "affected",
"version": "3.16.60",
"lessThan": "3.17",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.18.108",
"lessThan": "3.19",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.1.52",
"lessThan": "4.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.4.131",
"lessThan": "4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.9.98",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.39",
"lessThan": "4.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.16.7",
"lessThan": "4.17",
"versionType": "semver"
}
],
"programFiles": [
"drivers/char/virtio_console.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/char/virtio_console.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:27.750",
"references": [
{
"url": "https://git.kernel.org/stable/c/177ee901aa2bab02e7f1f8edbb814fd5e386ed62",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2e40c69b9c3448b9c6609cd02013da593b2e123b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/894f98e73983f37354214a89a3a7fd35bf9e3072",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8f6cfc3eca79b8e108d0823756101e2f4f9d811f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a80c33488e0bbe642ed803b13a4ac8078a70b507",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b1f39c2a676698cc64c8e105e08b25111a112ec6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e03522a990cd2e0f1a736eaa349a9df9ab8541c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f620c40ea6862feed84deb105568b21ec53a7830",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_console: do not free control-out buffers on remove\n\n__send_control_msg() publishes &portdev->cpkt as the control-out\nvirtqueue cookie. remove_vqs() walks every virtqueue and passes leftover\ncookies to free_buf(), which treats them as struct port_buffer and\nreads sgpages.\n\nIf a control message is still on c_ovq when the device is unbound,\nfree_buf() reads past the ports_device object.\n\nKASAN reported slab-out-of-bounds in free_buf():\n\n\tfree_buf\n\tremove_vqs\n\tvirtcons_remove\n\tunbind_store\n\nThe object was the ports_device allocated in virtcons_probe().\n\nDrain c_ovq without freeing. The packet lives in portdev and is released\nwith it."
}
],
"lastModified": "2026-10-03T11:18:23.233",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}