Executive brief
A vulnerability was identified in the Linux kernel's vDPA (vhost Data Path Acceleration) framework, which is used to optimize network and storage performance in virtualized environments. A local attacker could exploit this flaw to cause a system crash or potentially access sensitive information from the kernel's memory. This issue affects the stability and security of systems running affected versions of the Linux kernel, particularly those utilizing high-performance virtualization features.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the Linux kernel's vDPA (drivers/vdpa/vdpa.c) component. The root cause is a missing entry for the 'VDPA_ATTR_DEV_NET_CFG_MAX_VQP' attribute in the 'vdpa_nl_policy' structure. When parsing incoming Netlink messages (nlmsg), the kernel fails to validate the length of this specific attribute, leading to an invalid pointer in 'info->attrs'. A local attacker with low privileges can trigger this OOB read by sending a specially crafted Netlink message. This can result in a kernel panic (DoS) or the leakage of sensitive kernel memory. The issue has been patched in various stable branches including 6.1.47, 6.4.12, and the 6.5 release cycle.
Affected products
- Linux Linux Kernel 5.15.198 to 6.1.47, 6.2 to 6.4.12, 6.5-rc1 to 6.5-rc6
Timeline
- 2023-07-27: other: Initial patch submitted by Lin Ma
- 2025-10-04: disclosed: CVE published by kernel.org