vmci_host: fix a race condition in vmci_host_poll() causing GPF
Published Dec 24, 2025
4.7
MEDIUMCVSS 3.1
EPSS 0.22%
Description
During fuzzing, a general protection fault is observed in vmci_host_poll().
general protection fault, probably for non-canonical address 0xdffffc0000000019: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x00000000000000c8-0x00000000000000cf] RIP: 0010:__lock_acquire+0xf3/0x5e00 kernel/locking/lockdep.c:4926 <- omitting registers -> Call Trace: <TASK> lock_acquire+0x1a4/0x4a0 kernel/locking/lockdep.c:5672 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0xb3/0x100 kernel/locking/spinlock.c:162 add_wait_queue+0x3d/0x260 kernel/sched/wait.c:22 poll_wait include/linux/poll.h:49 [inline] vmci_host_poll+0xf8/0x2b0 drivers/misc/vmw_vmci/vmci_host.c:174 vfs_poll include/linux/poll.h:88 [inline] do_pollfd fs/select.c:873 [inline] do_poll fs/select.c:921 [inline] do_sys_poll+0xc7c/0x1aa0 fs/select.c:1015 __do_sys_ppoll fs/select.c:1121 [inline] __se_sys_ppoll+0x2cc/0x330 fs/select.c:1101 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x4e/0xa0 arch/x86/entry/common.c:82 entry_SYSCALL_64_after_hwframe+0x46/0xb0
Example thread interleaving that causes the general protection fault is as follows:
CPU1 (vmci_host_poll) CPU2 (vmci_host_do_init_context) ----- ----- // Read uninitialized context context = vmci_host_dev->context; // Initialize context vmci_host_dev->context = vmci_ctx_create(); vmci_host_dev->ct_type = VMCIOBJ_CONTEXT;
if (vmci_host_dev->ct_type == VMCIOBJ_CONTEXT) { // Dereferencing the wrong pointer poll_wait(..., &context->host_context); }
In this scenario, vmci_host_poll() reads vmci_host_dev->context first, and then reads vmci_host_dev->ct_type to check that vmci_host_dev->context is initialized. However, since these two reads are not atomically executed, there is a chance of a race condition as described above.
To fix this race condition, read vmci_host_dev->context after checking the value of vmci_host_dev->ct_type so that vmci_host_poll() always reads an initialized context.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 3.9
Unaffected
- ≥ 0, < 3.9
- ≥ 4.19.283, ≤ 4.19.*
- ≥ 5.10.180, ≤ 5.10.*
- ≥ 5.15.111, ≤ 5.15.*
- ≥ 5.4.243, ≤ 5.4.*
- ≥ 6.1.28, ≤ 6.1.*
- ≥ 6.2.15, ≤ 6.2.*
- ≥ 6.3.2, ≤ 6.3.*
- 6.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability affects systems running VMware virtualization with the VMCI driver. The race condition requires specific timing between poll operations and context initialization. The impact is limited to denial of service through a kernel crash in VMware guest environments.
Red Hat mitigation
To mitigate this issue, prevent the vmw_vmci module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.
References (14)
- https://access.redhat.com/security/cve/CVE-2023-54007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2424960 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205148 Advisory
- https://git.kernel.org/stable/c/2053e93ac15519ed1f1fe6eba79a33a4963be4a3
- https://git.kernel.org/stable/c/67e35824f861a05b44b19d38e16a83f653bd9d92
- https://git.kernel.org/stable/c/770d30b1355c6c8879973dd054fca9168def182c
- https://git.kernel.org/stable/c/85b4aa4eb2e3a0da111fd0a1cdbf00f986ac6b6b
- https://git.kernel.org/stable/c/ab64bd32b9fac27ff4737d63711b9db5e5462448
- https://git.kernel.org/stable/c/ae13381da5ff0e8e084c0323c3cc0a945e43e9c7
- https://git.kernel.org/stable/c/ca0f4ad2b7a36c799213ef0a213eb977a51e03dc
- https://git.kernel.org/stable/c/d22b2a35729cb1de311cb650cd67518a24e13fc9
- https://lore.kernel.org/linux-cve-announce/2025122429-CVE-2023-54007-89b1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2023-54007
- https://www.cve.org/CVERecord?id=CVE-2023-54007
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data