Answer in brief
CVE-2024-27066 records a Unknown severity vulnerability in virtio: packed: fix unmap leak for indirect desc table. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b319940f83c21bb4c1fabffe68a862be879a6193 <e142169aca5546ae6619c39a575cda8105362100 || >=b319940f83c21bb4c1fabffe68a862be879a6193 <75450ff8c6fe8755bf5b139b238eaf9739cfd64e || >=b319940f83c21bb4c1fabffe68a862be879a6193 <51bacd9d29bf98c3ebc65e4a0477bb86306b4140 || >=b319940f83c21bb4c1fabffe68a862be879a6193 <d5c0ed17fea60cca9bc3bf1278b49ba79242bbcd | e142169aca5546ae6619c39a575cda8105362100, 75450ff8c6fe8755bf5b139b238eaf9739cfd64e, 51bacd9d29bf98c3ebc65e4a0477bb86306b4140, d5c0ed17fea60cca9bc3bf1278b49ba79242bbcd |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not called by detach_buf_packed. if (unlikely(vq->do_unmap)) { curr = id; for (i = 0; i < state->num; i++) { vring_unmap_extra_packed(vq, &vq->packed.desc_extra[curr]); curr = vq->packed.desc_extra[curr].next; } } So the indirect desc table is not unmapped. This causes the unmap leak. So here, we check vq->use_dma_api instead. Synchronously, dma info is updated based on use_dma_api judgment This bug does not occur, because no driver use the premapped with indirect.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-27066 records a Unknown severity vulnerability in virtio: packed: fix unmap leak for indirect desc table. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b319940f83c21bb4c1fabffe68a862be879a6193 <e142169aca5546ae6619c39a575cda8105362100 || >=b319940f83c21bb4c1fabffe68a862be879a6193 <75450ff8c6fe8755bf5b139b238eaf9739cfd64e || >=b319940f83c21bb4c1fabffe68a862be879a6193 <51bacd9d29bf98c3ebc65e4a0477bb86306b4140 || >=b319940f83c21bb4c1fabffe68a862be879a6193 <d5c0ed17fea60cca9bc3bf1278b49ba79242bbcd | e142169aca5546ae6619c39a575cda8105362100, 75450ff8c6fe8755bf5b139b238eaf9739cfd64e, 51bacd9d29bf98c3ebc65e4a0477bb86306b4140, d5c0ed17fea60cca9bc3bf1278b49ba79242bbcd |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
May 1, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not called by detach_buf_packed. if (unlikely(vq->do_unmap)) { curr = id; for (i = 0; i < state->num; i++) { vring_unmap_extra_packed(vq, &vq->packed.desc_extra[curr]); curr = vq->packed.desc_extra[curr].next; } } So the indirect desc table is not unmapped. This causes the unmap leak. So here, we check vq->use_dma_api instead. Synchronously, dma info is updated based on use_dma_api judgment This bug does not occur, because no driver use the premapped with indirect.
Quoted source text, attributed separately from HOL analysis.