CVE-2026-97989

Source
https://cve.org/CVERecord?id=CVE-2026-97989
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97989.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97989
Downstream
Published
2026-09-25T10:23:22Z
Modified
2026-09-26T03:48:31Z
Summary
vduse: validate virtqueue alignment
Details

In the Linux kernel, the following vulnerability has been resolved:

vduse: validate virtqueue alignment

vduse_validate_config() only checks the upper bound of vq_align. Invalid values can therefore reach vring_create_virtqueue_map(). The split-ring helpers use align - 1 as a bit mask, so the alignment must be a non-zero power of two. A zero value makes vring_size() drop the descriptor and available-ring part and vring_init() leave the used ring pointer NULL.

The VIRTIO spec requires the used ring to start at an address aligned to at least 4 bytes. Reject values below VRING_USED_ALIGN_SIZE as well as non-power-of-two values before they reach the virtio ring helpers.

Opening a virtio-net device created with vq_align=0 triggered:

BUG: KASAN: null-ptr-deref in virtqueue_kick_prepare_split+0xe3/0x100 Read of size 2 at addr 0000000000000000 by task systemd-network/1062

Call Trace (relevant frames): dump_stack_lvl print_report kasan_report __asan_load2 virtqueue_kick_prepare_split+0xe3/0x100 virtqueue_kick_prepare+0x40/0x60 try_fill_recv+0x857/0x1250 virtnet_open+0x189/0x460 __dev_open+0x225/0x390 __dev_change_flags+0x368/0x3b0 netif_change_flags+0x56/0xc0 do_setlink.isra.0+0x68c/0x1e30

Validate the value before it reaches the virtio ring helpers.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97989.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c8a6153b6c59d95c0e091f053f6f180952ade91e
Fixed
c3c3b0839a1197530cc18f535062fc84dbdfc885
Fixed
fa2c25b4add57888acfa89e398389e267bff3dcf

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97989.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97989.json"