{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97993","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:18:58.209Z","datePublished":"2026-09-25T10:23:25.110Z","dateUpdated":"2026-10-03T11:01:20.553Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T11:01:20.553Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx\n\nvhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value\ninto v->config_ctx before checking it, so on failure the field briefly\nholds an ERR_PTR:\n\n\tctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);\n\tswap(ctx, v->config_ctx);\n\n\tif (!IS_ERR_OR_NULL(ctx))\n\t\teventfd_ctx_put(ctx);\n\n\tif (IS_ERR(v->config_ctx)) {\n\t\tlong ret = PTR_ERR(v->config_ctx);\n\n\t\tv->config_ctx = NULL;\n\t\treturn ret;\n\t}\n\nCommit 0bde59c1723a (\"vhost-vdpa: set v->config_ctx to NULL if\neventfd_ctx_fdget() fails\") added that clearing, and spelled out the\ninvariant the rest of the file relies on: \"we consider 'v->config_ctx'\nvalid if it is not NULL\".  The window between the swap and the clearing\nstill breaks it.  vhost_vdpa_config_cb() only tests for NULL, so a config\ninterrupt delivered inside the window hands the ERR_PTR to\neventfd_signal().\n\nCheck the fd before installing it instead.  That closes the window and\nmatches how vhost_vring_ioctl() handles the same failure for the vq call\nfd.\n\nIt also stops a rejected fd from tearing down a config interrupt that was\nworking: until now the swap replaced the live context and put it, so\nafter an EBADF the device silently stopped delivering config interrupts\nuntil userspace installed a new fd."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vhost/vdpa.c"],"versions":[{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"e260dc9fbfdae0978e7a8698f977fbb463a657be","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"66e73fa18910b39fea0941dea5fe091122240855","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"4fde085eb839fbb39c25cbba5d2a091ded394877","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"59fc7c1c6b4d325194ca45352180340092d95098","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"388c678639a0cebfd936b3e56c64ac6a371efec2","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"6b20b40f020bde236f6b8a08ff88d8653261ec2b","status":"affected","versionType":"git"},{"version":"776f395004d829bbbf18c159ed9beb517a208c71","lessThan":"e74a9fa50749b9940b4fb13199652325e08d3c4a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/vhost/vdpa.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.7","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc3","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.3-rc3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e260dc9fbfdae0978e7a8698f977fbb463a657be"},{"url":"https://git.kernel.org/stable/c/66e73fa18910b39fea0941dea5fe091122240855"},{"url":"https://git.kernel.org/stable/c/4fde085eb839fbb39c25cbba5d2a091ded394877"},{"url":"https://git.kernel.org/stable/c/59fc7c1c6b4d325194ca45352180340092d95098"},{"url":"https://git.kernel.org/stable/c/388c678639a0cebfd936b3e56c64ac6a371efec2"},{"url":"https://git.kernel.org/stable/c/65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a"},{"url":"https://git.kernel.org/stable/c/6b20b40f020bde236f6b8a08ff88d8653261ec2b"},{"url":"https://git.kernel.org/stable/c/e74a9fa50749b9940b4fb13199652325e08d3c4a"}],"title":"vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx","x_generator":{"engine":"bippy-1.2.0"}}}}