KernelScan.io

HIGH Introduced in 3.6

vhost-scsi MemTable Race

CVE-2026-93782

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

KernelScan AI7.6HIGH

01

In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhost-scsi translates guest response descriptors into userspace iovecs when commands are submitted. Target-core completes those commands asynchronously, so VHOST_SET_MEM_TABLE can replace the memory table while an in-flight command still retains response iovecs translated through the old table. If the old mapping is reused after VHOST_SET_MEM_TABLE returns, command completion can write the response to an unrelated userspace object. Flush the vhost-scsi backend after vhost_dev_ioctl() handles a device ioctl. This waits for in-flight commands that can still use the old response iovecs before the ioctl returns.

02

Engine v0.6.0

Risk summary

Products running virtualization hosts with the vhost-scsi backend enabled are at risk. A malicious guest VM can exploit a race between asynchronous SCSI command completion and guest memory table updates to corrupt host-side memory through stale response mappings, potentially escaping the VM boundary to execute code on the host. Hosts that do not use vhost-scsi or do not run untrusted VMs are unaffected.

Affecteddrivers/vhost/scsi.c (vhost-scsi)

Vulnerability analysis

The vhost-scsi subsystem translates guest I/O response descriptors into host-side memory mappings at command submission time, but the SCSI backend completes those commands asynchronously. While commands are still in flight, a device ioctl that updates the guest memory table can swap out the old table, leaving in-flight commands holding response mappings derived from the now-stale table. When such a command finishes, it writes its response through those outdated mappings, corrupting an unrelated host userspace object. The fix adds a backend flush after each device ioctl returns, ensuring all in-flight commands that could still reference the old memory table complete before the ioctl returns to the caller. A malicious guest VM on a host with the vhost-scsi backend enabled can trigger this by issuing SCSI I/O whose completion overlaps a guest memory layout change, and the guest requires no host-side privileges to do so.

03

BranchIntroducedFixed inPatch commit
6.123.66.12.111981c97d09c6b
6.183.66.18.536c1b802e36b0
mainline3.67.222598f55a4c2