Description
In the Linux kernel, the following vulnerability has been resolved:

vdpa_sim: fix cleanup after worker creation failure

vdpasim_create() leaves vdpasim->worker as an ERR_PTR when
kthread_run_worker() fails. The error path then drops the device
reference, which releases the partially initialized simulator.

vdpasim_free() unconditionally passes the worker pointer to
kthread_destroy_worker(), so the ERR_PTR is dereferenced and can trigger
a general protection fault.

Store the worker error, clear the pointer, and only clean up the worker
when it was successfully initialized. Also make the release path tolerate
partially initialized objects by guarding virtqueue and IOTLB cleanup,
since the same release path can be reached from other initialization
failures.

I found this bug myself, though the patch was written with AI assistance.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises during the initialization of a vdpa_sim device in the Linux kernel. If kthread_run_worker() fails, the vdpasim->worker member is left as an ERR_PTR. A subsequent call to vdpasim_free() then unconditionally passes this erroneous pointer to kthread_destroy_worker(), causing a general protection fault that brings down the kernel. The weakness is an unchecked use of an error value that is treated as a valid pointer, leading to a crash and loss of availability for the system.

Affected Systems

Any Linux installation that builds in the vdpa_sim subsystem and has not yet applied the patch is affected. No specific kernel release or version is listed, so all kernels containing this code prior to the fix are at risk.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. Attackers would need the ability to instantiate a vdpa_sim device, which generally requires privileged access or elevated kernel permissions. If utilized, the flaw would terminate the kernel, providing a denial of service but not directly allowing unauthorized code execution. The risk, while low in terms of exploit likelihood, remains significant because a crash can disrupt critical services.

Generated by OpenCVE AI on September 18, 2026 at 22:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fixed vdpa_sim implementation (commit 05ddc94afb69e36df59e88cfa9e5c7bf9d10cfd0).
  • If update is not immediately feasible, disable the vdpa_sim module or unbind the virtual DPDK device to prevent the vulnerable code from running.
  • As an additional precaution, restrict who can create vdpa_sim devices by tightening SELinux/AppArmor profiles and limiting capabilities such as CAP_SYS_ADMIN.

Generated by OpenCVE AI on September 18, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-572
CWE-588

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: fix cleanup after worker creation failure vdpasim_create() leaves vdpasim->worker as an ERR_PTR when kthread_run_worker() fails. The error path then drops the device reference, which releases the partially initialized simulator. vdpasim_free() unconditionally passes the worker pointer to kthread_destroy_worker(), so the ERR_PTR is dereferenced and can trigger a general protection fault. Store the worker error, clear the pointer, and only clean up the worker when it was successfully initialized. Also make the release path tolerate partially initialized objects by guarding virtqueue and IOTLB cleanup, since the same release path can be reached from other initialization failures. I found this bug myself, though the patch was written with AI assistance.
Title vdpa_sim: fix cleanup after worker creation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:31.216Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.493

Modified: 2026-09-17T17:17:05.493

Link: CVE-2026-90130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses
  • CWE-572

    Call to Thread run() instead of start()

  • CWE-588

    Attempt to Access Child of a Non-structure Pointer