Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64474

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc<br /> <br /> vfio_mig_get_next_state() walks vfio_from_fsm_table[] one step at a time,<br /> looping to skip optional states the device does not support until<br /> *next_fsm is supported. A blocked transition is encoded as<br /> VFIO_DEVICE_STATE_ERROR, which the trailing return reports as -EINVAL.<br /> <br /> The skip loop does not account for the ERROR sentinel.<br /> state_flags_table[ERROR] is ~0U and vfio_from_fsm_table[ERROR][*] is<br /> ERROR, so once *next_fsm becomes ERROR the loop condition stays true and<br /> *next_fsm never changes. The blocked arcs STOP_COPY -&gt; PRE_COPY and<br /> STOP_COPY -&gt; PRE_COPY_P2P map to ERROR yet pass the support check on a<br /> precopy-capable device, causing the loop to spin forever while holding<br /> the driver state mutex. This can result in a soft lockup, and a panic<br /> with softlockup_panic set.<br /> <br /> Terminate the skip loop on the ERROR sentinel so a blocked transition<br /> falls through to the existing return and reports -EINVAL.

Impacto