CVE-2026-97983
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
vduse: return compat ioctl results directly
The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then calls the native handler. Their different command sizes make native dispatch return -ENOIOCTLCMD.
For GET_FD, this overwrites receive_fd()'s return value after the descriptor is installed, leaking one fd per call. Return handled compat results directly and use native dispatch only for other commands.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 455a2a1af92651764e9eb42cec0d95ac142afc28 < 135ac58097fa5fc707bf392c5cececf59e4080c0 | affected |
| Linux | Linux | 455a2a1af92651764e9eb42cec0d95ac142afc28 < 48a4ee65e677559776349128e6a81a6041986c99 | affected |
| Linux | Linux | 7dd28904c42ee3b0728c0692dd3332c2c83e8f33 | affected |
| Linux | Linux | 7.1.5 < 7.2 | affected |
| Linux | Linux | 7.2 | affected |
| Linux | Linux | 0 < 7.2 | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/135ac58097fa5fc707bf392c5cececf59e4080c0
- https://git.kernel.org/stable/c/48a4ee65e677559776349128e6a81a6041986c99
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.