← All Advisories

CVE-2026-97993

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97993

Key Details

CVECVE-2026-97993
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx

vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value

into v->config_ctx before checking it, so on failure the field briefly

holds an ERR_PTR:

ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);

swap(ctx, v->config_ctx);

if (!IS_ERR_OR_NULL(ctx))

eventfd_ctx_put(ctx);

if (IS_ERR(v->config_ctx)) {

long ret = PTR_ERR(v->config_ctx);

v->config_ctx = NULL;

return ret;

}

Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if

eventfd_ctx_fdget() fails") added that clearing, and spelled out the

invariant the rest of the file relies on: "we consider 'v->config_ctx'

valid if it is not NULL". The window between the swap and the clearing

still breaks it. vhost_vdpa_config_cb() only tests for NULL, so a config

interrupt delivered inside the window hands the ERR_PTR to

eventfd_signal().

Check the fd before installing it instead. That closes the window and

matches how vhost_vring_ioctl() handles the same failure for the vq call

fd.

It also stops a rejected fd from tearing down a config interrupt that was

working: until now the swap replaced the live context and put it, so

after an EBADF the device silently stopped delivering config interrupts

until userspace installed a new fd. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97993
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97993