← All Advisories

CVE-2026-97995

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97995

Key Details

CVECVE-2026-97995
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

virtio_console: do not free control-out buffers on remove

__send_control_msg() publishes &portdev->cpkt as the control-out

virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover

cookies to free_buf(), which treats them as struct port_buffer and

reads sgpages.

If a control message is still on c_ovq when the device is unbound,

free_buf() reads past the ports_device object.

KASAN reported slab-out-of-bounds in free_buf():

free_buf

remove_vqs

virtcons_remove

unbind_store

The object was the ports_device allocated in virtcons_probe().

Drain c_ovq without freeing. The packet lives in portdev and is released

with it. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97995
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97995