CVE-2026-97995: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: virtio_console: do not free control-out buffers on remove __send_control_msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover cookies to free_buf(), which treats them as struct port_buffer and reads sgpages. If a control message is still on c_ovq when the device is unbound, free_buf() reads past the ports_device object. KASAN reported slab-out-of-bounds in free_buf(): free_buf remove_vqs virtcons_remove unbind_store The object was the ports_device allocated in virtcons_probe(). Drain c_ovq without freeing. The packet lives in portdev and is released with it.
Affected products
- Linux Linux: from 3.16.60, before 3.17 (fixed in 3.17); from 3.18.108, before 3.19 (fixed in 3.19); from 4.1.52, before 4.2 (fixed in 4.2); from 4.4.131, before 4.5 (fixed in 4.5); from 4.9.98, before 4.10 (fixed in 4.10); from 4.14.39, before 4.15 (fixed in 4.15); …
Published 2026-09-25. Last modified 2026-10-03.