Back

MEDIUM

vdpa/vp_vdpa: fix kfree a wrong pointer in vp_vdpa_remove

Published Dec 30, 2025

Description

In vp_vdpa_remove(), the code kfree(&vp_vdpa_mgtdev->mgtdev.id_table) uses a reference of pointer as the argument of kfree, which is the wrong pointer and then may hit crash like this:

Unable to handle kernel paging request at virtual address 00ffff003363e30c Internal error: Oops: 96000004 [#1] SMP Call trace: rb_next+0x20/0x5c ext4_readdir+0x494/0x5c4 [ext4] iterate_dir+0x168/0x1b4 __se_sys_getdents64+0x68/0x170 __arm64_sys_getdents64+0x24/0x30 el0_svc_common.constprop.0+0x7c/0x1bc do_el0_svc+0x2c/0x94 el0_svc+0x20/0x30 el0_sync_handler+0xb0/0xb4 el0_sync+0x160/0x180 Code: 54000220 f9400441 b4000161 aa0103e0 (f9400821) SMP: stopping secondary CPUs Starting crashdump kernel...

Affected products

Remediation

Red Hat statement

An invalid free occurs in vp_vdpa_remove because the driver calls kfree on the address of the id_table pointer field instead of the pointer value. This effectively passes a non heap address to kfree. The result is memory corruption or an immediate kernel crash during device removal. The crash can be triggered when unloading the vp_vdpa module or removing the associated PCI vDPA device. For the CVSS the PR is L in the paranoid scenario because removal actions typically require elevated capabilities such as device management permissions.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 30, 2025
Updated May 11, 2026
Reserved Dec 30, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 30, 2025
ENISA EUVD
Assigner Linux
Published Dec 30, 2025
Updated May 11, 2026
Exploited since n/a
EUVD-2022-55825