CVE-2026-43248 PUBLISHED

vhost: move vdpa group bound check to vhost_vdpa

Assigner: Linux
Reserved: 01.05.2026 Published: 06.05.2026 Updated: 06.05.2026

In the Linux kernel, the following vulnerability has been resolved:

vhost: move vdpa group bound check to vhost_vdpa

Remove duplication by consolidating these here. This reduces the posibility of a parent driver missing them.

While we're at it, fix a bug in vdpa_sim where a valid ASID can be assigned to a group equal to ngroups, causing an out of bound write.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from bda324fd037a6b0d44da5699574ce741ca161bc4 to ddb57354634b6ba851b79da45f1de42c646f27d0 (excl.)
  • affected from bda324fd037a6b0d44da5699574ce741ca161bc4 to 7441d35d14d9a3d66d925d90cb73c75394e6d454 (excl.)
  • affected from bda324fd037a6b0d44da5699574ce741ca161bc4 to 406db68f9cb976a8ddfafd631197264f2307e9c9 (excl.)
  • affected from bda324fd037a6b0d44da5699574ce741ca161bc4 to cd025c1e876b4e262e71398236a1550486a73ede (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.19 is affected
  • unaffected from 0 to 5.19 (excl.)
  • unaffected from 6.12.75 to 6.12.* (incl.)
  • unaffected from 6.18.16 to 6.18.* (incl.)
  • unaffected from 6.19.6 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References