Answer in brief
CVE-2026-97994 records a Unknown severity vulnerability in vhost/vdpa: reject VRING_NUM larger than device max. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4c8cf31885f69e86be0b5b9e6677a26797365e1d <1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4 || >=4c8cf31885f69e86be0b5b9e6677a26797365e1d <68232102f20fc961327fb9e0f605a7eaadf030a9 || >=4c8cf31885f69e86be0b5b9e6677a26797365e1d <59522639a7d71cff4e20d594d0b9ea30dd0c77e0 || >=4c8cf31885f69e86be0b5b9e6677a26797365e1d <ccb1dc7c527f8c925925cf92afc76ae590dac311 | 1d09201d81b7d3e276860cc7b7dbf6c6cbe8e9b4, 68232102f20fc961327fb9e0f605a7eaadf030a9, 59522639a7d71cff4e20d594d0b9ea30dd0c77e0, ccb1dc7c527f8c925925cf92afc76ae590dac311 |
| Linux/Linuxgeneric | 5.7 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: reject VRING_NUM larger than device max vhost_vring_set_num() accepts any non-zero power-of-two queue size that fits in 16 bits. vhost-vdpa then passes that value to set_vq_num() without comparing it with get_vq_num_max(). A process with access to /dev/vhost-vdpa-* can therefore configure a queue larger than the device advertises. With vdpa_sim, the worker can walk descriptors beyond the mapped descriptor ring. KASAN reports a 16-byte out-of-bounds read, corresponding to one vring_desc, in the vringh IOTLB path: BUG: KASAN: out-of-bounds in _copy_from_iter Read of size 16 copy_from_iotlb copydesc_iotlb vringh_getdesc_iotlb vdpasim_net_work Cache get_vq_num_max() immediately after reset. Some backends derive it from writable queue-size state, so querying it after SET_NUM may return the current size instead of the device capability. Invalidate the cached value before reset so a failed reset leaves SET_NUM disabled. For VHOST_SET_VRING_NUM, copy the complete vring state once and use the same index and size for validation, vq->num, and set_vq_num(). This ensures that validation and use operate on the same copied values.
Quoted source text, attributed separately from HOL analysis.