Junglewise Threat Intelligence

CVE-2026-74311: Linux kernel virtio RTC NULL pointer dereference during restore

CVE-2026-74311 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's virtio real-time clock (RTC) driver can crash a guest system during power management restore operations. When the system resumes from suspend, improperly managed virtual device queues cause the kernel to crash with a NULL pointer dereference, disrupting service availability and potentially affecting guest VM uptime and reliability.

Technical details

This is a NULL pointer dereference vulnerability in the virtio RTC driver's restore path (drivers/virtio/virtio_rtc_driver.c). The root cause is a resource management error: viortc_freeze() intentionally preserves existing virtqueues for alarm wake functionality, but viortc_restore() attempts to reinitialize those queues without first deleting them. If virtqueue reinitialization fails (particularly in vp_find_vqs_msix() on virtio-pci), the error path calls vp_del_vqs() against a newly allocated vp_dev->vqs array while vdev->vqs still references stale queue structures. This causes vp_del_vq() to dereference a NULL info pointer, crashing the guest kernel. The vulnerability requires the guest to undergo a suspend/resume cycle on a virtio-based system, which is common in virtualized environments.

Affected products

  • Linux Linux Kernel 5.10 and later (introduced in commit 0623c7592768)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-10: patched: Fix committed upstream as commit 548d2208455f14e6121404c6e30e997bfe0cd264
  • 2026-05-07: other: Fix authored by Jia Jia

References

Related threats