Answer in brief
CVE-2026-97993 records a Unknown severity vulnerability in vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=776f395004d829bbbf18c159ed9beb517a208c71 <388c678639a0cebfd936b3e56c64ac6a371efec2 || >=776f395004d829bbbf18c159ed9beb517a208c71 <65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a || >=776f395004d829bbbf18c159ed9beb517a208c71 <6b20b40f020bde236f6b8a08ff88d8653261ec2b || >=776f395004d829bbbf18c159ed9beb517a208c71 <e74a9fa50749b9940b4fb13199652325e08d3c4a | 388c678639a0cebfd936b3e56c64ac6a371efec2, 65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a, 6b20b40f020bde236f6b8a08ff88d8653261ec2b, e74a9fa50749b9940b4fb13199652325e08d3c4a |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into v->config_ctx before checking it, so on failure the field briefly holds an ERR_PTR: ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd); swap(ctx, v->config_ctx); if (!IS_ERR_OR_NULL(ctx)) eventfd_ctx_put(ctx); if (IS_ERR(v->config_ctx)) { long ret = PTR_ERR(v->config_ctx); v->config_ctx = NULL; return ret; } Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if eventfd_ctx_fdget() fails") added that clearing, and spelled out the invariant the rest of the file relies on: "we consider 'v->config_ctx' valid if it is not NULL". The window between the swap and the clearing still breaks it. vhost_vdpa_config_cb() only tests for NULL, so a config interrupt delivered inside the window hands the ERR_PTR to eventfd_signal(). Check the fd before installing it instead. That closes the window and matches how vhost_vring_ioctl() handles the same failure for the vq call fd. It also stops a rejected fd from tearing down a config interrupt that was working: until now the swap replaced the live context and put it, so after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd.
Quoted source text, attributed separately from HOL analysis.