{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93782","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.788Z","datePublished":"2026-09-24T16:02:14.457Z","dateUpdated":"2026-10-03T10:57:16.951Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:16.951Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-scsi: flush backend after device ioctls\n\nvhost-scsi translates guest response descriptors into userspace iovecs\nwhen commands are submitted.  Target-core completes those commands\nasynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while\nan in-flight command still retains response iovecs translated through the\nold table.\n\nIf the old mapping is reused after VHOST_SET_MEM_TABLE returns, command\ncompletion can write the response to an unrelated userspace object.\n\nFlush the vhost-scsi backend after vhost_dev_ioctl() handles a device\nioctl.  This waits for in-flight commands that can still use the old\nresponse iovecs before the ioctl returns."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The missing flush is in vhost_scsi_ioctl() after vhost_dev_ioctl() handles VHOST_SET_MEM_TABLE via vhost_set_memory() on /dev/vhost-scsi; the retained pointers are tvc_resp_iovs filled by vhost_scsi_setup_resp_iovs() from vhost_get_vq_desc() on the local virtio-scsi virtqueue, not a network PDU.\nAC:H - A guest can leave commands in target-core via vhost_scsi_handle_vq()->vhost_scsi_target_queue_cmd()->target_submit(), but cannot call VHOST_SET_MEM_TABLE; only the VMM issues that ioctl (memory hotplug or live migration), so the replacement that makes old HVAs reusable is outside the attacker's control.\nPR:L - The attacker is a VM tenant sending virtio-scsi I/O that plants those tvc_resp_iovs; vhost_scsi_open() and vhost_scsi_ioctl() have no capable() check, and the already-attached LIO tpg (VHOST_SCSI_SET_ENDPOINT by QEMU) lets that guest I/O run without host root.\nUI:N - The guest plants in-flight commands by kicking its own virtqueue; no other user must mount an image or open a file. A later VMM VHOST_SET_MEM_TABLE is ordinary hypervisor memory-listener bookkeeping, not a tricked interactive action.\nS:C - vhost_scsi_complete_cmd_work() copy_to_iter()s virtio_scsi_cmd_resp through stale tvc_resp_iovs (and vhost_scsi_copy_sgl_to_iov() through a stale read_iter) into the host QEMU mm, so guest-originated completion corrupts VMM userspace across the KVM guest-to-host boundary.\nC:H - After QEMU reuses the old HVA, completion writes into unrelated VMM objects; the copied_iov READ path (vhost_scsi_copy_iov_to_sgl() dup_iter, then vhost_scsi_copy_sgl_to_iov()) can copy LUN data into that remapped heap, which is leverageable to disclose host memory back to the guest.\nI:H - copy_to_iter() of the packed virtio_scsi_cmd_resp plus, when vhost_scsi_map_to_sgl() falls back to vhost_scsi_copy_iov_to_sgl() for misaligned I/O with sgl_count>BIO_MAX_VECS, a guest-influenced READ payload into the remapped HVA, corrupting QEMU heap objects and enabling VMM control-flow hijack.\nA:H - A reused QEMU mapping hit by that completion write corrupts VMM heap metadata and aborts QEMU, terminating the VM; an unmapped old HVA only hits the \"Faulted on virtio_scsi_cmd_resp\" path, but reuse after VHOST_SET_MEM_TABLE is the contract the ioctl was supposed to guarantee."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vhost/scsi.c"],"versions":[{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"6436411203d8c702ffc055700f1a6bde488ff681","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"cec088285adcc7ae23c119b6bbdb22270dc2de8f","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"e0bf6bed528693a6b32439ab122b34a34b66d96f","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"be2636e1b21fe860db918152abf2932638d06ed7","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"981c97d09c6b9560bb12dcc41f11ce59b1a48e97","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"6c1b802e36b05ebd9d41686c4dce6f06966af469","status":"affected","versionType":"git"},{"version":"057cbf49a1f08297877e46c82f707b1bfea806a8","lessThan":"22598f55a4c2b510b3df5e69e563387a963222ae","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vhost/scsi.c"],"versions":[{"version":"3.6","status":"affected"},{"version":"0","lessThan":"3.6","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6436411203d8c702ffc055700f1a6bde488ff681"},{"url":"https://git.kernel.org/stable/c/cec088285adcc7ae23c119b6bbdb22270dc2de8f"},{"url":"https://git.kernel.org/stable/c/e0bf6bed528693a6b32439ab122b34a34b66d96f"},{"url":"https://git.kernel.org/stable/c/be2636e1b21fe860db918152abf2932638d06ed7"},{"url":"https://git.kernel.org/stable/c/981c97d09c6b9560bb12dcc41f11ce59b1a48e97"},{"url":"https://git.kernel.org/stable/c/6c1b802e36b05ebd9d41686c4dce6f06966af469"},{"url":"https://git.kernel.org/stable/c/22598f55a4c2b510b3df5e69e563387a963222ae"}],"title":"vhost-scsi: flush backend after device ioctls","x_generator":{"engine":"bippy-1.2.0"}}}}