CVE-2026-64457 PUBLISHED

virtio_pci: fix vq info pointer lookup via wrong index

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

virtio_pci: fix vq info pointer lookup via wrong index

Unbinding a virtio balloon device:

<pre>echo virtio0 > /sys/bus/virtio/drivers/virtio_balloon/unbind </pre>

triggers a NULL pointer dereference. The dmesg says:

<pre>BUG: kernel NULL pointer dereference, address: 0000000000000008 [...] RIP: 0010:__list_del_entry_valid_or_report+0x5/0xf0 Call Trace: <TASK> vp_del_vqs+0x121/0x230 remove_common+0x135/0x150 virtballoon_remove+0xee/0x100 virtio_dev_remove+0x3b/0x80 device_release_driver_internal+0x187/0x2c0 unbind_store+0xb9/0xe0 kernfs_fop_write_iter.llvm.11660790530567441834+0xf6/0x180 vfs_write+0x2a9/0x3b0 ksys_write+0x5c/0xd0 do_syscall_64+0x54/0x230 entry_SYSCALL_64_after_hwframe+0x29/0x31 [...] </TASK> </pre>

The virtio_balloon device registers 5 queues (inflate, deflate, stats, free_page, reporting) but only the first two are unconditional. The stats, free_page and reporting queues are each conditional on their respective feature bits. When any of these features are absent, the corresponding vqs_info entry has name == NULL, creating holes in the array.

The root cause is an indexing mismatch introduced when vq info storage was changed to be passed as an argument. vp_find_vqs_msix() and vp_find_vqs_intx() store the info pointer at vp_dev->vqs[i], where 'i' is the caller's sparse array index. However, the virtqueue itself gets vq->index assigned from queue_idx, a dense index that skips NULL entries. When holes exist, 'i' and queue_idx diverge. Later, vp_del_vqs() looks up info via vp_dev->vqs[vq->index] using the dense index into the sparsely-populated array, and hits NULL.

Fix this by storing info at vp_dev->vqs[queue_idx] instead of vp_dev->vqs[i], so the store index matches the lookup index (vq->index). Apply the fix to both the MSIX and INTX paths.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 89a1c435aec269d109ed46ca7bbb10fa8edf7ace to 41e6dc1a10036c9f47057033f19af7e52ec464b6 (excl.)
  • affected from 89a1c435aec269d109ed46ca7bbb10fa8edf7ace to 075bc3c779e1ea7294afabdcb7e0a49536959b28 (excl.)
  • affected from 89a1c435aec269d109ed46ca7bbb10fa8edf7ace to 64a4c0befa77bcc01076aec9f93863ffd4ed06b7 (excl.)
  • affected from 89a1c435aec269d109ed46ca7bbb10fa8edf7ace to f7d380fb525c13bdd114369a1979c80c346e6abc (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.11 is affected
  • unaffected from 0 to 6.11 (excl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References