CVE-2026-93782
Błąd w vhost-scsi w jądrze Linux umożliwia zapis odpowiedzi do niepowiązanego obiektu w przestrzeni użytkownika.
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through the old table. If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command completion can write the response to an unrelated userspace object. Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device ioctl. This waits for in-flight commands that can still use the old response iovecs before the ioctl returns.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-09-24 17:17:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:47 UTC |
- https://git.kernel.org/stable/c/22598f55a4c2b510b3df5e69e563387a963222ae (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6436411203d8c702ffc055700f1a6bde488ff681 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6c1b802e36b05ebd9d41686c4dce6f06966af469 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/981c97d09c6b9560bb12dcc41f11ce59b1a48e97 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/be2636e1b21fe860db918152abf2932638d06ed7 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/cec088285adcc7ae23c119b6bbdb22270dc2de8f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/e0bf6bed528693a6b32439ab122b34a34b66d96f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)