HIGH Introduced in 6.9
virtio-fs QueueSetup DoubleFree
CVE-2026-93827
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI6.7MEDIUM
01Description
In the Linux kernel, the following vulnerability has been resolved: virtio-fs: avoid double-free on failed queue setup virtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling virtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both pointers and returns an error to virtio_fs_probe(). virtio_fs_probe() then drops the last kobject reference, and virtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves dangling pointers in struct virtio_fs and can trigger a double-free during probe failure cleanup. Set fs->vqs and fs->mq_map to NULL immediately after kfree() in the virtio_fs_setup_vqs() error path so that the later kobject release sees an uninitialized state and kfree(NULL) becomes harmless. This can be reproduced when a broken virtio-fs device advertises more request queues than the transport actually provides. In that case virtio_find_vqs() fails while setting up the extra queue, and the probe path reaches the double-free cleanup sequence.
02KernelScan AI Analysis
Risk summary
A virtio-fs device that advertises more request queues than the transport provides triggers a double-free in the guest kernel during probe failure cleanup. The host or VMM that controls device configuration can trigger this, potentially corrupting the guest kernel heap. Products running as VM guests with virtio-fs are at risk; bare-metal deployments are unaffected.
Vulnerability analysis
A virtio-fs driver cleanup path can free the same memory twice when device queue setup fails. If the virtio device advertises more request queues than the transport actually provides, the error path during probing frees internal arrays but leaves dangling pointers in the driver state. The probe failure handler then triggers a release callback that frees those same arrays again, causing a double-free that corrupts the kernel heap. The fix clears the pointers immediately after the first free, so the later release path safely does nothing instead of freeing stale memory. This bug is reachable only when a virtio-fs device is present, which requires a virtualization environment where the host or hypervisor controls device configuration — a malicious or misconfigured host can trigger it during guest device probing, but an unprivileged guest process cannot reach this path on its own.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 6.9 | 6.12.111 | 3fbc5ee776fe |
| 6.18 | 6.9 | 6.18.53 | 20ef4739b329 |
| mainline | 6.9 | 7.2 | 6af3330ec5d5 |