kernel: vhost-vdpa: protect config_ctx from being freed under the config callback
cve CVE-2026-97992 3 sources, 4 claims · Watch
Red Hat writes:
kernel: vhost-vdpa: protect config_ctx from being freed under the config callback the claim
kernel: vhost-vdpa: protect config_ctx from being freed under the config callback the claim
- Severity they disagree
- unknown GitHub advisoriesmoderate Red Hat
- CVSS
- 5.5 Red Hat
- Vendor
- Linux NVD
- Product
- Linux NVD
- CWE
- CWE-825 Red Hat
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-09-25 | first spoke of it: In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect... | GitHub advisories |
| 2026-09-25 | first spoke of it: In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: protect config_ctx from being freed under the config callback vhost_vdpa_config_cb() loads v->config_ctx and signals it without taking a reference and without holding any lock: struct eventfd_ctx *config_ctx = v->config_ctx; if (config_ctx) eventfd_signal(config_ctx); VHOST_VDPA_SET_CONFIG_CALL replaces that field and drops what is normally the last reference to the old context: swap(ctx, v->config_ctx); if (ctx) eventfd_ctx_put(ctx); eventfd_ctx_put() drops the last kref and frees the context immediately, with no RCU grace period, so a callback that has already loaded the pointer goes on to dereference freed memory. The two sides share no lock: the ioctl runs under vhost_dev.mutex, while the parent invokes the callback from its own interrupt or workqueue context. This is not the reopen refcount underflow fixed by commit f6bbf0010ba0 ("vhost-vdpa: fix use-after-free of v->config_ctx"), which was about vhost_vdpa_config_put() leaving a stale pointer behind. Here the pointer is maintained correctly and it is the read side that is unprotected. With VDUSE as the parent this is reachable from userspace with access to /dev/vduse (root by default). VDUSE_DEV_INJECT_CONFIG_IRQ queues dev->inject, and vduse_dev_irq_inject() runs the callback under VDUSE's own dev->irq_lock, which vhost does not hold. vduse_dev_reset() does flush_work(&dev->inject), but VHOST_VDPA_SET_CONFIG_CALL never goes through reset, so an inject already in flight is not waited for. A process that injects config interrupts on the VDUSE fd while another thread swaps the call fd on the vhost-vdpa fd hits it in seconds: BUG: KASAN: slab-use-after-free in native_queued_spin_lock_slowpath Read of size 4 at addr ffff888107d21808 by task kworker/u17:1/2993 Workqueue: vduse-irq vduse_dev_irq_inject Call Trace: native_queued_spin_lock_slowpath+0x97/0x5b0 _raw_spin_lock_irqsave+0xd4/0xe0 eventfd_signal_mask+0x69/0x120 vhost_vdpa_config_cb+0x34/0x50 vduse_dev_irq_inject+0x46/0x60 process_one_work+0x468/0x950 Allocated by task 2992: do_eventfd+0x50/0x200 __x64_sys_eventfd2+0x2e/0x40 Freed by task 2992: eventfd_ctx_put+0xb9/0xc0 vhost_vdpa_unlocked_ioctl+0x116c/0x2190 Add a spinlock covering every access to config_ctx, so the callback either signals a context that is still alive or observes NULL, and the put happens only once no callback can reach the old value. Clearing the parent's callback before the put would not be enough: of the in-tree set_config_cb() implementations only VDUSE takes a lock, the rest store the pointer unlocked, so that would not order against an in-flight invocation. | NVD |
| 2026-09-25 | first spoke of it: kernel: vhost-vdpa: protect config_ctx from being freed under the config callback | Red Hat |
What it is to other things
In words only, so not counted until a person confirms one:
| affects | linux/linuxNVD says “Linux · Linux” |
| made_by | linuxNVD says “Linux” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| CVSS cvss | Red Hat | 5.5receipt
What the source handed over{
"CVE": "CVE-2026-97992",
"CWE": "CWE-825",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541298",
"bugzilla_description": "kernel: vhost-vdpa: protect config_ctx from being freed under the config callback",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-25T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-97992.json",
"severity": "moderate"
} | — | ||||
| CVSS vector cvss_vector | Red Hat | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:Hreceipt
What the source handed over{
"CVE": "CVE-2026-97992",
"CWE": "CWE-825",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541298",
"bugzilla_description": "kernel: vhost-vdpa: protect config_ctx from being freed under the config callback",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-25T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-97992.json",
"severity": "moderate"
} | — | ||||
| CWE cwe | Red Hat | CWE-825receipt
What the source handed over{
"CVE": "CVE-2026-97992",
"CWE": "CWE-825",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541298",
"bugzilla_description": "kernel: vhost-vdpa: protect config_ctx from being freed under the config callback",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-25T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-97992.json",
"severity": "moderate"
} | — | ||||
| Product product | NVD | Linuxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "5a075ee2398929d5cc1393666f219c35332becb1",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "62be4e3e5f5f947fbf765b914cebdc478f715d12",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: protect config_ctx from being freed under the config callback\n\nvhost_vdpa_config_cb() loads v->config_ctx and signals it without taking\na reference and without holding any lock:\n\n\tstruct eventfd_ctx *config_ctx = v->config_ctx;\n\n\tif (config_ctx)\n\t\teventfd_signal(config_ctx);\n\nVHOST_VDPA_SET_CONFIG_CALL replaces that field and drops what is normally\nthe last reference to the old context:\n\n\tswap(ctx, v->config_ctx);\n\n\tif (ctx)\n\t\teventfd_ctx_put(ctx);\n\neventfd_ctx_put() drops the last kref and frees the context immediately,\nwith no RCU grace period, so a callback that has already loaded the\npointer goes on to dereference freed memory. The two sides share no\nlock: the ioctl runs under vhost_dev.mutex, while the parent invokes the\ncallback from its own interrupt or workqueue context.\n\nThis is not the reopen refcount underflow fixed by commit f6bbf0010ba0\n(\"vhost-vdpa: fix use-after-free of v->config_ctx\"), which was about\nvhost_vdpa_config_put() leaving a stale pointer behind. Here the pointer\nis maintained correctly and it is the read side that is unprotected.\n\nWith VDUSE as the parent this is reachable from userspace with access to\n/dev/vduse (root by default). VDUSE_DEV_INJECT_CONFIG_IRQ queues\ndev->inject, and vduse_dev_irq_inject() runs the callback under VDUSE's\nown dev->irq_lock, which vhost does not hold. vduse_dev_reset() does\nflush_work(&dev->inject), but VHOST_VDPA_SET_CONFIG_CALL never goes\nthrough reset, so an inject already in flight is not waited for. A\nprocess that injects config interrupts on the VDUSE fd while another\nthread swaps the call fd on the vhost-vdpa fd hits it in seconds:\n\n BUG: KASAN: slab-use-after-free in native_queued_spin_lock_slowpath\n Read of size 4 at addr ffff888107d21808 by task kworker/u17:1/2993\n Workqueue: vduse-irq vduse_dev_irq_inject\n Call Trace:\n native_queued_spin_lock_slowpath+0x97/0x5b0\n _raw_spin_lock_irqsave+0xd4/0xe0\n eventfd_signal_mask+0x69/0x120\n vhost_vdpa_config_cb+0x34/0x50\n vduse_dev_irq_inject+0x46/0x60\n process_one_work+0x468/0x950\n\n Allocated by task 2992:\n do_eventfd+0x50/0x200\n __x64_sys_eventfd2+0x2e/0x40\n\n Freed by task 2992:\n eventfd_ctx_put+0xb9/0xc0\n vhost_vdpa_unlocked_ioctl+0x116c/0x2190\n\nAdd a spinlock covering every access to config_ctx, so the callback\neither signals a context that is still alive or observes NULL, and the\nput happens only once no callback can reach the old value.\n\nClearing the parent's callback before the put would not be enough: of the\nin-tree set_config_cb() implementations only VDUSE takes a lock, the rest\nstore the pointer unlocked, so that would not order against an in-flight\ninvocation."
}
],
"id": "CVE-2026-97992",
"lastModified": "2026-09-25T11:17:27.343",
"metrics": {},
"published": "2026-09-25T11:17:27.343",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/5a075ee2398929d5cc1393666f219c35332becb1"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/62be4e3e5f5f947fbf765b914cebdc478f715d12"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Received"
}
} | — | ||||
| Severity severity conflict | GitHub advisories | unknownreceipt
This source has not kept a receipt for this claim yet. The next update that reads it will. | — | ||||
| Severity severity conflict | Red Hat | moderate A flaw that is harder to exploit, or whose impact is limited. receipt
What the source handed over{
"CVE": "CVE-2026-97992",
"CWE": "CWE-825",
"advisories": [],
"affected_packages": [],
"bugzilla": "2541298",
"bugzilla_description": "kernel: vhost-vdpa: protect config_ctx from being freed under the config callback",
"cvss3_score": "5.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-25T00:00:00Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-97992.json",
"severity": "moderate"
} | medium | ||||
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "5a075ee2398929d5cc1393666f219c35332becb1",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "62be4e3e5f5f947fbf765b914cebdc478f715d12",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: protect config_ctx from being freed under the config callback\n\nvhost_vdpa_config_cb() loads v->config_ctx and signals it without taking\na reference and without holding any lock:\n\n\tstruct eventfd_ctx *config_ctx = v->config_ctx;\n\n\tif (config_ctx)\n\t\teventfd_signal(config_ctx);\n\nVHOST_VDPA_SET_CONFIG_CALL replaces that field and drops what is normally\nthe last reference to the old context:\n\n\tswap(ctx, v->config_ctx);\n\n\tif (ctx)\n\t\teventfd_ctx_put(ctx);\n\neventfd_ctx_put() drops the last kref and frees the context immediately,\nwith no RCU grace period, so a callback that has already loaded the\npointer goes on to dereference freed memory. The two sides share no\nlock: the ioctl runs under vhost_dev.mutex, while the parent invokes the\ncallback from its own interrupt or workqueue context.\n\nThis is not the reopen refcount underflow fixed by commit f6bbf0010ba0\n(\"vhost-vdpa: fix use-after-free of v->config_ctx\"), which was about\nvhost_vdpa_config_put() leaving a stale pointer behind. Here the pointer\nis maintained correctly and it is the read side that is unprotected.\n\nWith VDUSE as the parent this is reachable from userspace with access to\n/dev/vduse (root by default). VDUSE_DEV_INJECT_CONFIG_IRQ queues\ndev->inject, and vduse_dev_irq_inject() runs the callback under VDUSE's\nown dev->irq_lock, which vhost does not hold. vduse_dev_reset() does\nflush_work(&dev->inject), but VHOST_VDPA_SET_CONFIG_CALL never goes\nthrough reset, so an inject already in flight is not waited for. A\nprocess that injects config interrupts on the VDUSE fd while another\nthread swaps the call fd on the vhost-vdpa fd hits it in seconds:\n\n BUG: KASAN: slab-use-after-free in native_queued_spin_lock_slowpath\n Read of size 4 at addr ffff888107d21808 by task kworker/u17:1/2993\n Workqueue: vduse-irq vduse_dev_irq_inject\n Call Trace:\n native_queued_spin_lock_slowpath+0x97/0x5b0\n _raw_spin_lock_irqsave+0xd4/0xe0\n eventfd_signal_mask+0x69/0x120\n vhost_vdpa_config_cb+0x34/0x50\n vduse_dev_irq_inject+0x46/0x60\n process_one_work+0x468/0x950\n\n Allocated by task 2992:\n do_eventfd+0x50/0x200\n __x64_sys_eventfd2+0x2e/0x40\n\n Freed by task 2992:\n eventfd_ctx_put+0xb9/0xc0\n vhost_vdpa_unlocked_ioctl+0x116c/0x2190\n\nAdd a spinlock covering every access to config_ctx, so the callback\neither signals a context that is still alive or observes NULL, and the\nput happens only once no callback can reach the old value.\n\nClearing the parent's callback before the put would not be enough: of the\nin-tree set_config_cb() implementations only VDUSE takes a lock, the rest\nstore the pointer unlocked, so that would not order against an in-flight\ninvocation."
}
],
"id": "CVE-2026-97992",
"lastModified": "2026-09-25T11:17:27.343",
"metrics": {},
"published": "2026-09-25T11:17:27.343",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/5a075ee2398929d5cc1393666f219c35332becb1"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/62be4e3e5f5f947fbf765b914cebdc478f715d12"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Received"
}
} | — | ||||
| Vendor vendor | NVD | Linuxreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "5a075ee2398929d5cc1393666f219c35332becb1",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
},
{
"lessThan": "62be4e3e5f5f947fbf765b914cebdc478f715d12",
"status": "affected",
"version": "776f395004d829bbbf18c159ed9beb517a208c71",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/vhost/vdpa.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix"
}
]
}
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: protect config_ctx from being freed under the config callback\n\nvhost_vdpa_config_cb() loads v->config_ctx and signals it without taking\na reference and without holding any lock:\n\n\tstruct eventfd_ctx *config_ctx = v->config_ctx;\n\n\tif (config_ctx)\n\t\teventfd_signal(config_ctx);\n\nVHOST_VDPA_SET_CONFIG_CALL replaces that field and drops what is normally\nthe last reference to the old context:\n\n\tswap(ctx, v->config_ctx);\n\n\tif (ctx)\n\t\teventfd_ctx_put(ctx);\n\neventfd_ctx_put() drops the last kref and frees the context immediately,\nwith no RCU grace period, so a callback that has already loaded the\npointer goes on to dereference freed memory. The two sides share no\nlock: the ioctl runs under vhost_dev.mutex, while the parent invokes the\ncallback from its own interrupt or workqueue context.\n\nThis is not the reopen refcount underflow fixed by commit f6bbf0010ba0\n(\"vhost-vdpa: fix use-after-free of v->config_ctx\"), which was about\nvhost_vdpa_config_put() leaving a stale pointer behind. Here the pointer\nis maintained correctly and it is the read side that is unprotected.\n\nWith VDUSE as the parent this is reachable from userspace with access to\n/dev/vduse (root by default). VDUSE_DEV_INJECT_CONFIG_IRQ queues\ndev->inject, and vduse_dev_irq_inject() runs the callback under VDUSE's\nown dev->irq_lock, which vhost does not hold. vduse_dev_reset() does\nflush_work(&dev->inject), but VHOST_VDPA_SET_CONFIG_CALL never goes\nthrough reset, so an inject already in flight is not waited for. A\nprocess that injects config interrupts on the VDUSE fd while another\nthread swaps the call fd on the vhost-vdpa fd hits it in seconds:\n\n BUG: KASAN: slab-use-after-free in native_queued_spin_lock_slowpath\n Read of size 4 at addr ffff888107d21808 by task kworker/u17:1/2993\n Workqueue: vduse-irq vduse_dev_irq_inject\n Call Trace:\n native_queued_spin_lock_slowpath+0x97/0x5b0\n _raw_spin_lock_irqsave+0xd4/0xe0\n eventfd_signal_mask+0x69/0x120\n vhost_vdpa_config_cb+0x34/0x50\n vduse_dev_irq_inject+0x46/0x60\n process_one_work+0x468/0x950\n\n Allocated by task 2992:\n do_eventfd+0x50/0x200\n __x64_sys_eventfd2+0x2e/0x40\n\n Freed by task 2992:\n eventfd_ctx_put+0xb9/0xc0\n vhost_vdpa_unlocked_ioctl+0x116c/0x2190\n\nAdd a spinlock covering every access to config_ctx, so the callback\neither signals a context that is still alive or observes NULL, and the\nput happens only once no callback can reach the old value.\n\nClearing the parent's callback before the put would not be enough: of the\nin-tree set_config_cb() implementations only VDUSE takes a lock, the rest\nstore the pointer unlocked, so that would not order against an in-flight\ninvocation."
}
],
"id": "CVE-2026-97992",
"lastModified": "2026-09-25T11:17:27.343",
"metrics": {},
"published": "2026-09-25T11:17:27.343",
"references": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/5a075ee2398929d5cc1393666f219c35332becb1"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/62be4e3e5f5f947fbf765b914cebdc478f715d12"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/bf35c8948ab7a3eaf1f724fa1e870e3f73a1749b"
},
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"url": "https://git.kernel.org/stable/c/f4a93f15ed1c8406ba5c8e5b28cafacb2b3bcd11"
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"vulnStatus": "Received"
}
} | — |