CVE-2026-97983: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: vduse: return compat ioctl results directly The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then calls the native handler. Their different command sizes make native dispatch return -ENOIOCTLCMD. For GET_FD, this overwrites receive_fd()'s return value after the descriptor is installed, leaking one fd per call. Return handled compat results directly and use native dispatch only for other commands.
Affected products
- Linux Linux: from 7.1.5, before 7.2 (fixed in 7.2); from 7.2, before 7.2.7 (fixed in 7.2.7)
Published 2026-09-25. Last modified 2026-09-25.