Executive brief
A vulnerability in the Linux kernel's Xen 9p file system driver could allow a system crash or potential unauthorized code execution. The issue occurs when the system attempts to clean up resources twice due to a synchronization error during back-end notifications. This could lead to a denial-of-service (system crash) or be leveraged by an attacker with access to the local network environment to compromise the host system.
Technical details
A race condition exists in the Linux kernel's 9p/xen transport layer (net/9p/trans_xen.c). The 'xenwatch' thread can race with other back-end change notifications, leading to concurrent calls to xen_9pfs_front_free(). This results in a double-free of the front-end state, triggering a general protection fault. The fix introduces proper locking and state checks in xen_9pfs_front_remove and xen_9pfs_front_init to ensure that only one caller can release the front-end state at a time. The vulnerability is classified as CWE-415 (Double Free).
Affected products
- Linux Linux Kernel 4.14.308 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-01-29: other: Patch authored
- 2026-05-06: disclosed: CVE published