Description
In the Linux kernel, the following vulnerability has been resolved:

Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition

The VMBus module initialization function, hv_acpi_init(), currently
does nothing when running in the root partition and root is not nested
in another VM. But the initialization function reports success, so the
VMBus module is indeed loaded. VMBus functionality is not actually
needed, but the VMBus module must be loaded so that hv_vmbus_exists()
can answer correctly. Furthermore, the mshv_root dependency on the
VMBus module is needed as described in the commit message for
840b740a35bf ("mshv: Add conditional VMBus dependency").

Loading the VMBus module without actually initializing it causes
failures if the module should later be unloaded. The module unload code
tries to clean up things that were never initialized, resulting in
memory faults and a panic.

Fix this by having VMBus module exit function perform the same
check for non-nested root partition, and do nothing in such a
case, just like hv_acpi_init().

In the long run, the code that manages the Hyper-V provided SynIC
should be refactored to better coordinate the requirements of
root partition scenarios and normal VM scenarios, and to hopefully
remove the hv_vmbus_exists() dependnecy between mshv_root and
VMBus modules. Preventing the current unload failure scenario is
an expediency until such a refactoring is done.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Panic (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

A flaw in the Hyper‑V VMBus kernel module allows the module to be loaded in the root partition while its initialization routine performs no work, yet it reports success. Subsequent unloading of the module triggers its exit routine, which attempts to clean up resources that were never allocated, causing memory faults and resulting in a kernel panic. This denial of service impacts the host operating system by bringing the kernel down.

Affected Systems

The issue targets the Linux kernel VMBus driver used on Hyper‑V virtual machines. It manifests in the root partition of a virtualized host when the system is not running as a nested VM. Any Linux kernel containing the unpatched hv_acpi_init and exit functions is vulnerable, regardless of specific version details.

Risk and Exploitability

The EPSS score is reported as less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the problem can be triggered by any entity that can unload the VMBus module on the host, typically requiring privileged access. If an attacker can force the module to unload, they can cause a kernel panic, potentially disrupting services unless mitigated by system resilience or monitoring.

Generated by OpenCVE AI on September 20, 2026 at 03:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix for VMBus module initialization and cleanup
  • If an immediate kernel upgrade is not possible, prevent the VMBus module from being unloaded on systems that do not run nested VMs
  • Monitor system logs for kernel panic events related to the VMBus driver and apply the patch as soon as it becomes available

Generated by OpenCVE AI on September 20, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition The VMBus module initialization function, hv_acpi_init(), currently does nothing when running in the root partition and root is not nested in another VM. But the initialization function reports success, so the VMBus module is indeed loaded. VMBus functionality is not actually needed, but the VMBus module must be loaded so that hv_vmbus_exists() can answer correctly. Furthermore, the mshv_root dependency on the VMBus module is needed as described in the commit message for 840b740a35bf ("mshv: Add conditional VMBus dependency"). Loading the VMBus module without actually initializing it causes failures if the module should later be unloaded. The module unload code tries to clean up things that were never initialized, resulting in memory faults and a panic. Fix this by having VMBus module exit function perform the same check for non-nested root partition, and do nothing in such a case, just like hv_acpi_init(). In the long run, the code that manages the Hyper-V provided SynIC should be refactored to better coordinate the requirements of root partition scenarios and normal VM scenarios, and to hopefully remove the hv_vmbus_exists() dependnecy between mshv_root and VMBus modules. Preventing the current unload failure scenario is an expediency until such a refactoring is done.
Title Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:09.529Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.350

Modified: 2026-09-17T17:17:01.350

Link: CVE-2026-90097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses

No weakness.