CVE-2026-97983

Summary

In the Linux kernel, the following vulnerability has been resolved:

vduse: return compat ioctl results directly

The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then calls the native handler. Their different command sizes make native dispatch return -ENOIOCTLCMD.

For GET_FD, this overwrites receive_fd()'s return value after the descriptor is installed, leaking one fd per call. Return handled compat results directly and use native dispatch only for other commands.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux455a2a1af92651764e9eb42cec0d95ac142afc28 < 135ac58097fa5fc707bf392c5cececf59e4080c0affected
LinuxLinux455a2a1af92651764e9eb42cec0d95ac142afc28 < 48a4ee65e677559776349128e6a81a6041986c99affected
LinuxLinux7dd28904c42ee3b0728c0692dd3332c2c83e8f33affected
LinuxLinux7.1.5 < 7.2affected
LinuxLinux7.2affected
LinuxLinux0 < 7.2unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc3 <= *unaffected

Weaknesses

References