Executive brief
A vulnerability was identified in the Linux kernel's virtualization components (vDPA) that could allow a local user to cause a system crash or potentially gain unauthorized access. The issue stems from a technical error in how the system handles virtual device groups, which can lead to memory corruption. This affects systems using vDPA for high-performance networking or storage in virtualized environments.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the Linux kernel's vDPA (vhost Data Path Acceleration) subsystem, specifically within the vdpa_sim driver. The root cause is a logic error where a valid Address Space Identifier (ASID) could be assigned to a group index equal to 'ngroups', bypassing intended boundary checks. This consolidation of checks into vhost_vdpa addresses the risk of parent drivers missing these validations. A local attacker with low privileges can exploit this via IOCTL calls (VHOST_VDPA_SET_GROUP_ASID) to trigger memory corruption, potentially leading to a denial of service or local privilege escalation. Patches have been released for multiple stable kernel branches including 6.12.75, 6.18.16, and 6.19.6.
Affected products
- Linux Linux Kernel 5.19 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-03-04: patched: Patches applied to stable branches.