{"api_version":"1","generated_at":"2026-10-03T07:06:48+00:00","cve":"CVE-2026-93827","urls":{"html":"https://cve.report/CVE-2026-93827","api":"https://cve.report/api/cve/CVE-2026-93827.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93827","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93827"},"summary":{"title":"virtio-fs: avoid double-free on failed queue setup","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-fs: avoid double-free on failed queue setup\n\nvirtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling\nvirtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both\npointers and returns an error to virtio_fs_probe().\n\nvirtio_fs_probe() then drops the last kobject reference, and\nvirtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves\ndangling pointers in struct virtio_fs and can trigger a double-free during\nprobe failure cleanup.\n\nSet fs->vqs and fs->mq_map to NULL immediately after kfree() in the\nvirtio_fs_setup_vqs() error path so that the later kobject release sees an\nuninitialized state and kfree(NULL) becomes harmless.\n\nThis can be reproduced when a broken virtio-fs device advertises more\nrequest queues than the transport actually provides. In that case\nvirtio_find_vqs() fails while setting up the extra queue, and the probe\npath reaches the double-free cleanup sequence.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:16","updated_at":"2026-09-25 13:17:23"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/6af3330ec5d5fb8c06c04eb520a71cf73ea5a765","name":"https://git.kernel.org/stable/c/6af3330ec5d5fb8c06c04eb520a71cf73ea5a765","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad","name":"https://git.kernel.org/stable/c/3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/20ef4739b329bb09cff11dd2458795a50674658e","name":"https://git.kernel.org/stable/c/20ef4739b329bb09cff11dd2458795a50674658e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93827","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93827","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9 3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9 20ef4739b329bb09cff11dd2458795a50674658e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9 6af3330ec5d5fb8c06c04eb520a71cf73ea5a765 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93827","cve":"CVE-2026-93827","epss":"0.001400000","percentile":"0.027860000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/fuse/virtio_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad","status":"affected","version":"a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9","versionType":"git"},{"lessThan":"20ef4739b329bb09cff11dd2458795a50674658e","status":"affected","version":"a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9","versionType":"git"},{"lessThan":"6af3330ec5d5fb8c06c04eb520a71cf73ea5a765","status":"affected","version":"a8f62f50b4e4ea92a938fca2ec1bd108d7f210e9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/fuse/virtio_fs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.9"},{"lessThan":"6.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"6.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-fs: avoid double-free on failed queue setup\n\nvirtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling\nvirtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both\npointers and returns an error to virtio_fs_probe().\n\nvirtio_fs_probe() then drops the last kobject reference, and\nvirtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves\ndangling pointers in struct virtio_fs and can trigger a double-free during\nprobe failure cleanup.\n\nSet fs->vqs and fs->mq_map to NULL immediately after kfree() in the\nvirtio_fs_setup_vqs() error path so that the later kobject release sees an\nuninitialized state and kfree(NULL) becomes harmless.\n\nThis can be reproduced when a broken virtio-fs device advertises more\nrequest queues than the transport actually provides. In that case\nvirtio_find_vqs() fails while setting up the extra queue, and the probe\npath reaches the double-free cleanup sequence."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The triggering field is virtio_fs_config.num_request_queues, read by virtio_cread_le() in virtio_fs_setup_vqs() from virtio_fs_probe() via virtio_dev_probe() after virtio_pci_probe()/register_virtio_device() binds a VIRTIO_ID_FS device; those bytes come from local PCI/MMIO/vDPA config space, not a network protocol message.\nAC:L - A device that advertises more request queues than it exposes makes virtio_find_vqs()->vp_setup_vq() fail (-EINVAL when index >= vp_modern_get_num_queues(), or -ENOENT on queue size 0); virtio_fs_setup_vqs() then kfree's fs->vqs and fs->mq_map and virtio_fs_probe() always kobject_put()s into the second free, with no race.\nPR:N - virtio_fs_probe()/virtio_fs_setup_vqs() have no capable() or credential check; MODULE_DEVICE_TABLE(virtio, id_table) autoloads virtiofs and virtio_dev_probe() binds a VIRTIO_ID_FS device at enumeration or hotplug, so a malicious virtio-fs backend needs no account on the guest.\nUI:N - The double-free runs in the probe error path (virtio_fs_setup_vqs() failure, then kobject_put() into virtio_fs_ktype_release()) when the device appears; virtio_fs_add_instance() and a virtiofs mount are never reached, so no victim must mount or open anything.\nS:U - virtio_fs_ktype_release() double-frees the guest kernel kmalloc objects fs->vqs and fs->mq_map; that is device-to-guest heap corruption inside the same guest kernel, not a write into host virtiofsd or a KVM/IOMMU escape.\nC:H - kfree(fs->vqs) and kfree(fs->mq_map) in virtio_fs_setup_vqs() leave dangling pointers that virtio_fs_ktype_release() frees again; a slab double-free of that virtio_fs_vq array and per-CPU mq_map lets those objects overlap so the attacker can read adjacent kernel heap.\nI:H - The same second kfree of fs->vqs and fs->mq_map corrupts the SLUB freelist for those kmalloc objects and is an arbitrary-free primitive, enabling heap overwrite and control-flow hijack in the guest kernel.\nA:H - Double-free of fs->vqs and fs->mq_map in virtio_fs_ktype_release() after virtio_find_vqs() fails oopses or panics the guest during probe cleanup (KASAN invalid-free, SLUB poisoned-freelist BUG, or panic_on_oops)."}]}],"providerMetadata":{"dateUpdated":"2026-09-25T12:43:36.887Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/3fbc5ee776fefbc6ea34d2518f1f5f90aa2e1dad"},{"url":"https://git.kernel.org/stable/c/20ef4739b329bb09cff11dd2458795a50674658e"},{"url":"https://git.kernel.org/stable/c/6af3330ec5d5fb8c06c04eb520a71cf73ea5a765"}],"title":"virtio-fs: avoid double-free on failed queue setup","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93827","datePublished":"2026-09-24T16:03:05.795Z","dateReserved":"2026-09-18T17:59:28.792Z","dateUpdated":"2026-09-25T12:43:36.887Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:16","lastModifiedDate":"2026-09-25 13:17:23","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93827","Ordinal":"1","Title":"virtio-fs: avoid double-free on failed queue setup","CVE":"CVE-2026-93827","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93827","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio-fs: avoid double-free on failed queue setup\n\nvirtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling\nvirtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both\npointers and returns an error to virtio_fs_probe().\n\nvirtio_fs_probe() then drops the last kobject reference, and\nvirtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves\ndangling pointers in struct virtio_fs and can trigger a double-free during\nprobe failure cleanup.\n\nSet fs->vqs and fs->mq_map to NULL immediately after kfree() in the\nvirtio_fs_setup_vqs() error path so that the later kobject release sees an\nuninitialized state and kfree(NULL) becomes harmless.\n\nThis can be reproduced when a broken virtio-fs device advertises more\nrequest queues than the transport actually provides. In that case\nvirtio_find_vqs() fails while setting up the extra queue, and the probe\npath reaches the double-free cleanup sequence.","Type":"Description","Title":"virtio-fs: avoid double-free on failed queue setup"}]}}}