CVE-2026-64474
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc<br />
<br />
vfio_mig_get_next_state() walks vfio_from_fsm_table[] one step at a time,<br />
looping to skip optional states the device does not support until<br />
*next_fsm is supported. A blocked transition is encoded as<br />
VFIO_DEVICE_STATE_ERROR, which the trailing return reports as -EINVAL.<br />
<br />
The skip loop does not account for the ERROR sentinel.<br />
state_flags_table[ERROR] is ~0U and vfio_from_fsm_table[ERROR][*] is<br />
ERROR, so once *next_fsm becomes ERROR the loop condition stays true and<br />
*next_fsm never changes. The blocked arcs STOP_COPY -> PRE_COPY and<br />
STOP_COPY -> PRE_COPY_P2P map to ERROR yet pass the support check on a<br />
precopy-capable device, causing the loop to spin forever while holding<br />
the driver state mutex. This can result in a soft lockup, and a panic<br />
with softlockup_panic set.<br />
<br />
Terminate the skip loop on the ERROR sentinel so a blocked transition<br />
falls through to the existing return and reports -EINVAL.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/7f2d6b31089e48db4653df832c9a6afdde9a1c29
- https://git.kernel.org/stable/c/8e872c07e40d51a66dee7b280a23a460a2e1e3fa
- https://git.kernel.org/stable/c/a26b499b757cfc8bbff1088bb1b844639e250893
- https://git.kernel.org/stable/c/a3a8afa2f6e7f0dc266d08f02be3f3054241ba47
- https://git.kernel.org/stable/c/ed7d5599e6c398da74845767cd1e6a8370a160fc



