← All Advisories

CVE-2026-97994

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97994

Key Details

CVECVE-2026-97994
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

vhost/vdpa: reject VRING_NUM larger than device max

vhost_vring_set_num() accepts any non-zero power-of-two queue size that

fits in 16 bits. vhost-vdpa then passes that value to set_vq_num()

without comparing it with get_vq_num_max().

A process with access to /dev/vhost-vdpa-* can therefore configure a

queue larger than the device advertises. With vdpa_sim, the worker can

walk descriptors beyond the mapped descriptor ring. KASAN reports a

16-byte out-of-bounds read, corresponding to one vring_desc, in the

vringh IOTLB path:

BUG: KASAN: out-of-bounds in _copy_from_iter

Read of size 16

copy_from_iotlb

copydesc_iotlb

vringh_getdesc_iotlb

vdpasim_net_work

Cache get_vq_num_max() immediately after reset. Some backends derive

it from writable queue-size state, so querying it after SET_NUM may

return the current size instead of the device capability. Invalidate

the cached value before reset so a failed reset leaves SET_NUM

disabled.

For VHOST_SET_VRING_NUM, copy the complete vring state once and use

the same index and size for validation, vq->num, and set_vq_num().

This ensures that validation and use operate on the same copied values. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97994
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97994