Description
In the Linux kernel, the following vulnerability has been resolved:

virtio_balloon: quiesce balloon work before device shutdown

Commit 8bd2fa086a04 ("virtio: break and reset virtio devices on
device_shutdown()") added a generic virtio bus .shutdown handler that
breaks and resets every virtio device during device_shutdown(), i.e. on
reboot and kexec.

virtio_balloon provides no .shutdown of its own, so that generic path
runs while the balloon's asynchronous work is still armed. Once the
device has been broken, virtqueue_add_inbuf() in
virtballoon_free_page_report() returns -EIO and trips its
WARN_ON_ONCE(). On a kernel booted with panic_on_warn that turns an
ordinary reboot, for example a kexec based upgrade, into a fatal panic
in the middle of device_shutdown(), so the machine never reaches the
new kernel.

Relaxing that single WARN_ON_ONCE() would only hide the symptom: the
inflate/deflate and OOM paths do not warn, they call
wait_event(vb->acked, ...) and would instead block forever on a broken
queue that can no longer complete. The device has to be quiesced, not
just kept quiet.

Add a .shutdown handler that quiesces the balloon via the shared
virtballoon_quiesce() helper while the device is still alive, and only
then breaks and resets it via virtio_device_shutdown(). Unlike
virtballoon_remove() the balloon workqueue is not destroyed, as shutdown
does not free the device and cancel_work_sync() together with stop_update
already prevent any further work from being queued.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through kernel panic during shutdown or reboot
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s virtio balloon driver had no shutdown handler; when the generic virtio bus shutdown path ran during device_shutdown(), the balloon’s asynchronous work remained active. This caused a WARN_ON_ONCE after the device was broken, and if panic_on_warn is enabled, the result is a kernel panic. The failure prevents the system from booting into a new kernel via normal reboot or kexec based upgrade, effectively denying service for the affected host.

Affected Systems

All Linux kernel installations that ship with the virtio_balloon driver prior to the patch, regardless of distribution, are affected. The problem is mitigated by applying the official kernel update that adds a shutdown handler that quiesces the balloon before resetting the device.

Risk and Exploitability

The vulnerability is not currently in the CISA KEV list and has an EPSS score below 1%. Exploitation does not require active attacker control; the issue surfaces automatically on normal device shutdown or system reboot, making it a low effort, high impact denial of service. The CVSS metric is not provided, but the impact warrants prompt mitigation.

Generated by OpenCVE AI on September 18, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that implements a proper shutdown handler for virtio_balloon
  • If a kernel upgrade is delayed, remove or disable virtio_balloon devices until the patch is applied
  • Temporarily configure the system to avoid panic_on_warn during shutdown as a short‑term mitigation, though a full patch is required for lasting resolution

Generated by OpenCVE AI on September 18, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-668

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: virtio_balloon: quiesce balloon work before device shutdown Commit 8bd2fa086a04 ("virtio: break and reset virtio devices on device_shutdown()") added a generic virtio bus .shutdown handler that breaks and resets every virtio device during device_shutdown(), i.e. on reboot and kexec. virtio_balloon provides no .shutdown of its own, so that generic path runs while the balloon's asynchronous work is still armed. Once the device has been broken, virtqueue_add_inbuf() in virtballoon_free_page_report() returns -EIO and trips its WARN_ON_ONCE(). On a kernel booted with panic_on_warn that turns an ordinary reboot, for example a kexec based upgrade, into a fatal panic in the middle of device_shutdown(), so the machine never reaches the new kernel. Relaxing that single WARN_ON_ONCE() would only hide the symptom: the inflate/deflate and OOM paths do not warn, they call wait_event(vb->acked, ...) and would instead block forever on a broken queue that can no longer complete. The device has to be quiesced, not just kept quiet. Add a .shutdown handler that quiesces the balloon via the shared virtballoon_quiesce() helper while the device is still alive, and only then breaks and resets it via virtio_device_shutdown(). Unlike virtballoon_remove() the balloon workqueue is not destroyed, as shutdown does not free the device and cancel_work_sync() together with stop_update already prevent any further work from being queued.
Title virtio_balloon: quiesce balloon work before device shutdown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:30.537Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.370

Modified: 2026-09-17T17:17:05.370

Link: CVE-2026-90129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere