CVE-2026-74580
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
vhost: reset the vring metadata cache on vring reconfiguration<br />
<br />
vq->meta_iotlb[] caches the vhost_iotlb_map that backs each vring<br />
metadata region, and iotlb_access_ok() returns early on a cache hit,<br />
taking the hit as proof that the region has already been validated:<br />
<br />
if (vhost_vq_meta_fetch(vq, addr, len, type))<br />
return true;<br />
<br />
The cache is reset on VHOST_IOTLB_UPDATE and VHOST_IOTLB_INVALIDATE, on<br />
device IOTLB (re)initialisation and on vq reset, but not when<br />
VHOST_SET_VRING_ADDR replaces vq->desc, vq->avail and vq->used, nor when<br />
VHOST_SET_VRING_NUM changes the region sizes.<br />
<br />
With a device IOTLB attached both ioctls are accepted while the vq is<br />
live, and neither validates the addresses at ioctl time: vq_access_ok()<br />
and vq_log_used_access_ok() return true early because the addresses are<br />
GIOVAs, deferring validation to prefetch time. Once the cache has been<br />
populated that deferred validation no longer runs -- vq_meta_prefetch()<br />
hits the stale entry and returns true -- and vhost_vq_meta_fetch() keeps<br />
translating through the old mapping as<br />
<br />
map->addr + addr - map->start<br />
<br />
for an address the mapping no longer covers. vhost_copy_to_user() and<br />
vhost_copy_from_user() consume the result with __copy_to_user() and<br />
__copy_from_user(), which do not check it either, so a subsequent used<br />
ring update or descriptor fetch accesses memory outside the region the<br />
IOTLB actually maps.<br />
<br />
Reset the metadata cache whenever the vring is reconfigured, so the new<br />
addresses are pushed back through iotlb_access_ok()&#39;s slow path.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/13fa6f32a56a386a82bd7451644c494beed034af
- https://git.kernel.org/stable/c/5224bd37e37d36076a550d99b2aebba33939fd95
- https://git.kernel.org/stable/c/54617e9119be2eb728ecdd8d977b99c99d4c498a
- https://git.kernel.org/stable/c/6fa3e9b1fe856259555a7e22f3f3082e7827fd9b
- https://git.kernel.org/stable/c/b70ebe0bba254e093dd5fd4c0c170941ce83eb85
- https://git.kernel.org/stable/c/cf363a7a02ce132ef1f58084fdb13e1a3b7da7e7
- https://git.kernel.org/stable/c/de845981da67a6b049080c87e605130b0c30adc5
- https://git.kernel.org/stable/c/f1e21108e3ddfcce62f6cad4ebd7b5674543c9e6


