Executive brief
The Linux kernel's VDUSE (vDPA Device in Userspace) driver contains a race condition that can lead to use-after-free when opening a virtual device. An attacker with local access can exploit concurrent operations to cause a kernel crash or potentially execute arbitrary code, affecting the stability and security of virtualization operations on the affected system.
Technical details
This is a use-after-free race condition in the VDUSE device open path (vduse_dev_open()). The vulnerability occurs because the function releases vduse_lock before acquiring dev->lock, creating a window where a concurrent VDUSE_DESTROY_DEV operation can remove and free the device object from the IDR (ID Radix tree) while the open path is still trying to access it. The fix maintains vduse_lock throughout the lookup and initial lock acquisition, ensuring atomicity. The vulnerability is exploitable with local access and requires the ability to trigger concurrent device open and destroy operations.
Affected products
- Linux Linux kernel all versions with VDUSE support (introduced in v5.15 and later)
Timeline
- 2026-08-15: disclosed: CVE-2026-74313 published
- 2026-07-24: patched: Fix merged into Linux stable branches
- 2026-05-08: other: Fix authored by Qihang Tang