Description
In the Linux kernel, the following vulnerability has been resolved: vhost: move vdpa group bound check to vhost_vdpa Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them. While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
2.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (11)
Linux/Linux
< 5.19
Linux/Linux
5.19
Linux/Linux
6.12.75 - 6.12.*
Linux/Linux
6.18.16 - 6.18.*
Linux/Linux
6.19.6 - 6.19.*
Linux/Linux
7.0
Linux/Linux
bda324fd037a6b0d44da5699574ce741ca161bc4 - 406db68f9cb976a8ddfafd631197264f2307e9c9
Linux/Linux
bda324fd037a6b0d44da5699574ce741ca161bc4 - 7441d35d14d9a3d66d925d90cb73c75394e6d454
Linux/Linux
bda324fd037a6b0d44da5699574ce741ca161bc4 - cd025c1e876b4e262e71398236a1550486a73ede
Linux/Linux
bda324fd037a6b0d44da5699574ce741ca161bc4 - ddb57354634b6ba851b79da45f1de42c646f27d0
... and 1 more
Published
May 06, 2026
Tracked Since
May 06, 2026