Executive brief
A vulnerability in the Linux kernel's vDPA (vhost Data Path Acceleration) subsystem could allow a local user to cause a system crash. vDPA is a technology used to speed up network and storage performance in virtualized environments. By exploiting a flaw in how the system handles driver assignments, an attacker could trigger a memory error that leads to a kernel panic, disrupting services and operations.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's vDPA implementation (drivers/vdpa/vdpa.c). When a driver is probed via __driver_attach(), the bus' match() callback is invoked without holding the device lock. This allows concurrent access to the driver_override field without synchronization, potentially leading to a UAF condition if the field is modified or freed while being accessed. An attacker with local access could exploit this race condition to cause a kernel oops or denial of service. The issue has been resolved by migrating to the generic driver_override infrastructure provided by the driver core, which handles the necessary locking internally.
Affected products
- Linux Linux Kernel 5.17 to 6.18.32, 7.0.9
Timeline
- 2026-03-24: patched: Initial fix commit authored
- 2026-06-24: disclosed: CVE published