Executive brief
A flaw in the Linux kernel's virtio real-time clock (RTC) driver can crash a guest system during power management restore operations. When the system resumes from suspend, improperly managed virtual device queues cause the kernel to crash with a NULL pointer dereference, disrupting service availability and potentially affecting guest VM uptime and reliability.
Technical details
This is a NULL pointer dereference vulnerability in the virtio RTC driver's restore path (drivers/virtio/virtio_rtc_driver.c). The root cause is a resource management error: viortc_freeze() intentionally preserves existing virtqueues for alarm wake functionality, but viortc_restore() attempts to reinitialize those queues without first deleting them. If virtqueue reinitialization fails (particularly in vp_find_vqs_msix() on virtio-pci), the error path calls vp_del_vqs() against a newly allocated vp_dev->vqs array while vdev->vqs still references stale queue structures. This causes vp_del_vq() to dereference a NULL info pointer, crashing the guest kernel. The vulnerability requires the guest to undergo a suspend/resume cycle on a virtio-based system, which is common in virtualized environments.
Affected products
- Linux Linux Kernel 5.10 and later (introduced in commit 0623c7592768)
Timeline
- 2026-08-15: disclosed
- 2026-06-10: patched: Fix committed upstream as commit 548d2208455f14e6121404c6e30e997bfe0cd264
- 2026-05-07: other: Fix authored by Jia Jia