vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx
Published Sep 25, 2026
No CVSS score
EPSS 0.21%
Description
vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into v->config_ctx before checking it, so on failure the field briefly holds an ERR_PTR:
ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd); swap(ctx, v->config_ctx);
if (!IS_ERR_OR_NULL(ctx)) eventfd_ctx_put(ctx);
if (IS_ERR(v->config_ctx)) { long ret = PTR_ERR(v->config_ctx);
v->config_ctx = NULL; return ret; }
Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if eventfd_ctx_fdget() fails") added that clearing, and spelled out the invariant the rest of the file relies on: "we consider 'v->config_ctx' valid if it is not NULL". The window between the swap and the clearing still breaks it. vhost_vdpa_config_cb() only tests for NULL, so a config interrupt delivered inside the window hands the ERR_PTR to eventfd_signal().
Check the fd before installing it instead. That closes the window and matches how vhost_vring_ioctl() handles the same failure for the vq call fd.
It also stops a rejected fd from tearing down a config interrupt that was working: until now the swap replaced the live context and put it, so after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.8
Unaffected
- ≥ 0, < 5.8
- ≥ 5.10.271, ≤ 5.10.*
- ≥ 5.15.222, ≤ 5.15.*
- ≥ 6.1.189, ≤ 6.1.*
- ≥ 6.12.111, ≤ 6.12.*
- ≥ 6.18.53, ≤ 6.18.*
- ≥ 6.6.158, ≤ 6.6.*
- ≥ 7.2.7, ≤ 7.2.*
- 7.3-rc3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86647 Advisory
- https://git.kernel.org/stable/c/388c678639a0cebfd936b3e56c64ac6a371efec2
- https://git.kernel.org/stable/c/4fde085eb839fbb39c25cbba5d2a091ded394877
- https://git.kernel.org/stable/c/59fc7c1c6b4d325194ca45352180340092d95098
- https://git.kernel.org/stable/c/65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a
- https://git.kernel.org/stable/c/66e73fa18910b39fea0941dea5fe091122240855
- https://git.kernel.org/stable/c/6b20b40f020bde236f6b8a08ff88d8653261ec2b
- https://git.kernel.org/stable/c/e260dc9fbfdae0978e7a8698f977fbb463a657be
- https://git.kernel.org/stable/c/e74a9fa50749b9940b4fb13199652325e08d3c4a
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data