HIGH Introduced in 3.6
vhost-scsi MemTable Race
CVE-2026-93782
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
KernelScan AI7.6HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through the old table. If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command completion can write the response to an unrelated userspace object. Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device ioctl. This waits for in-flight commands that can still use the old response iovecs before the ioctl returns.
02KernelScan AI Analysis
Risk summary
Products running virtualization hosts with the vhost-scsi backend enabled are at risk. A malicious guest VM can exploit a race between asynchronous SCSI command completion and guest memory table updates to corrupt host-side memory through stale response mappings, potentially escaping the VM boundary to execute code on the host. Hosts that do not use vhost-scsi or do not run untrusted VMs are unaffected.
Vulnerability analysis
The vhost-scsi subsystem translates guest I/O response descriptors into host-side memory mappings at command submission time, but the SCSI backend completes those commands asynchronously. While commands are still in flight, a device ioctl that updates the guest memory table can swap out the old table, leaving in-flight commands holding response mappings derived from the now-stale table. When such a command finishes, it writes its response through those outdated mappings, corrupting an unrelated host userspace object. The fix adds a backend flush after each device ioctl returns, ensuring all in-flight commands that could still reference the old memory table complete before the ioctl returns to the caller. A malicious guest VM on a host with the vhost-scsi backend enabled can trigger this by issuing SCSI I/O whose completion overlaps a guest memory layout change, and the guest requires no host-side privileges to do so.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 3.6 | 6.12.111 | 981c97d09c6b |
| 6.18 | 3.6 | 6.18.53 | 6c1b802e36b0 |
| mainline | 3.6 | 7.2 | 22598f55a4c2 |