All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path
@ 2026-08-15  6:10 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:10 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

vduse: hold vduse_lock across IDR lookup in open path

vduse_dev_open() looks up struct vduse_dev through the IDR and then
acquires dev->lock only after vduse_lock has been dropped.

This leaves a window where a concurrent VDUSE_DESTROY_DEV can remove the
same object from the IDR and free it before the open path locks the
device, leading to a use-after-free.

Close this race by keeping vduse_lock held until dev->lock has been
acquired in the open path, matching the lock ordering already used by
the destroy path.

The Linux kernel CVE team has assigned CVE-2026-74313 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 5.15.212 with commit 35483c5306e09b3190ff937089d404a78012695c
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 6.1.178 with commit 5c1560be8aa6849356455af67518d35c551cbd95
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 6.6.145 with commit 93ed4692f2299a40346025979f40e4a9b7b33af7
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 6.12.97 with commit d94e2947203aead590fd63f667d316d4475d65af
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 6.18.40 with commit a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 7.1.5 with commit 79e12c891940b0c4c75881b7fd82a8cbb8ac97be
	Issue introduced in 5.15 with commit c8a6153b6c59d95c0e091f053f6f180952ade91e and fixed in 7.2-rc1 with commit e440e077748939839d9f76e24383b76b785f80ce

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74313
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/vdpa/vdpa_user/vduse_dev.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/35483c5306e09b3190ff937089d404a78012695c
	https://git.kernel.org/stable/c/5c1560be8aa6849356455af67518d35c551cbd95
	https://git.kernel.org/stable/c/93ed4692f2299a40346025979f40e4a9b7b33af7
	https://git.kernel.org/stable/c/d94e2947203aead590fd63f667d316d4475d65af
	https://git.kernel.org/stable/c/a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2
	https://git.kernel.org/stable/c/79e12c891940b0c4c75881b7fd82a8cbb8ac97be
	https://git.kernel.org/stable/c/e440e077748939839d9f76e24383b76b785f80ce

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:34 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:10 CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.