KernelScan.io

HIGH Introduced in 6.9

virtio-fs QueueSetup DoubleFree

CVE-2026-93827

CVSS 8.4 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI6.7MEDIUM

01

In the Linux kernel, the following vulnerability has been resolved: virtio-fs: avoid double-free on failed queue setup virtio_fs_setup_vqs() allocates fs->vqs and fs->mq_map before calling virtio_find_vqs(). If virtio_find_vqs() fails, the error path frees both pointers and returns an error to virtio_fs_probe(). virtio_fs_probe() then drops the last kobject reference, and virtio_fs_ktype_release() frees fs->vqs and fs->mq_map again. This leaves dangling pointers in struct virtio_fs and can trigger a double-free during probe failure cleanup. Set fs->vqs and fs->mq_map to NULL immediately after kfree() in the virtio_fs_setup_vqs() error path so that the later kobject release sees an uninitialized state and kfree(NULL) becomes harmless. This can be reproduced when a broken virtio-fs device advertises more request queues than the transport actually provides. In that case virtio_find_vqs() fails while setting up the extra queue, and the probe path reaches the double-free cleanup sequence.

02

Engine v0.6.0

Risk summary

A virtio-fs device that advertises more request queues than the transport provides triggers a double-free in the guest kernel during probe failure cleanup. The host or VMM that controls device configuration can trigger this, potentially corrupting the guest kernel heap. Products running as VM guests with virtio-fs are at risk; bare-metal deployments are unaffected.

Affectedfs/fuse/virtio_fs.c (virtio-fs)

Vulnerability analysis

A virtio-fs driver cleanup path can free the same memory twice when device queue setup fails. If the virtio device advertises more request queues than the transport actually provides, the error path during probing frees internal arrays but leaves dangling pointers in the driver state. The probe failure handler then triggers a release callback that frees those same arrays again, causing a double-free that corrupts the kernel heap. The fix clears the pointers immediately after the first free, so the later release path safely does nothing instead of freeing stale memory. This bug is reachable only when a virtio-fs device is present, which requires a virtualization environment where the host or hypervisor controls device configuration — a malicious or misconfigured host can trigger it during guest device probing, but an unprivileged guest process cannot reach this path on its own.

03

BranchIntroducedFixed inPatch commit
6.126.96.12.1113fbc5ee776fe
6.186.96.18.5320ef4739b329
mainline6.97.26af3330ec5d5