Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97952— sunvdc: unmap LDC cookies when the descriptor send fails

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: sunvdc:在描述符发送失败时取消映射 LDC cookies 函数会将请求的页面映射到 LDC(逻辑域通道)通道的映射表(通过 ),填充描述符,并在通过 触发门铃之前将其标记为 。当触发失败时,错误处理路径仅打印一条消息,而描述符仍保持 状态,且 cookies 永远不会被取消映射。 通常情况下,当对端完成描述符时,映射会在 中释放——但从未发送门铃的描述符永远不会被完成;此外,由于失败时未推进 ,重置路径( ,遍历区间 )也不会访问该描述符。因此,映射表条目会永久泄漏

AI Predicted 5.5 Difficulty: Moderate EPSS 0.18% · P7

Affected Version Matrix 28

VendorProduct Version RangeStatus
Linux Linux a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< eb9c5f6747fe98b83c78cb5476a914e91d50e8e8 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 24564576be423f3b5d7e67cd7df848ac66646497 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 9251573e7cf7d797ae4a30b2a236af8242237a61 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< b0de6463667e9bb9dc14a83a9c24c1b6b3f7b5f7 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< ab81a5c1014a38dab0fb402609fd866b0bcb4726 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 57835952566f0be9b365a6eb3a70b397a9d5ef47 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< f3322baa3a8ac87730feae952c1146269d78e098 affected
a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec< 0c6da21fa35e03fc74f09895433ccd6d4a9c3530 affected
… +20 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97952

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
sunvdc: unmap LDC cookies when the descriptor send fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sunvdc: unmap LDC cookies when the descriptor send fails __send_request() maps the request's pages into the LDC channel's map table (ldc_map_sg()), fills in the descriptor and marks it VIO_DESC_READY before ringing the doorbell via __vdc_tx_trigger(). When the trigger fails, the error path only prints a message: the descriptor stays READY and the cookies are never unmapped. The mapping is normally released in vdc_end_one() when the peer completes the descriptor - but a descriptor whose doorbell was never sent will never complete, and since dr->prod is not advanced on failure, the reset path (vdc_requeue_inflight(), which walks [cons, prod)) never visits it either. The map table entries are leaked permanently. Since commit a11f6ca9aef9 ("sunvdc: Do not spin in an infinite loop when vio_ldc_send() returns EAGAIN") trigger failures occur in practice under load, so every resulting I/O error also leaks one request's worth of entries from the fixed-size (8192 entries per channel) map table. Because the allocator hands out contiguous ranges, fragmentation makes large multi-segment requests fail first as the table drains, until ldc_map_sg() fails permanently and the disk is dead until reboot. It also makes any retry-based recovery unusable: requeuing the request on -EAGAIN remaps the pages on every attempt, overwriting desc->cookies and orphaning the previous mapping, so the table drains at the retry rate. This is the memory exhaustion observed when the requeue approach was first tested in October 2025. Roll back on failure: unmap the cookies, mark the descriptor FREE again and clear the request entry. If the trigger failed with -ENOTCONN, __vdc_tx_trigger() has already reset the port, which tears down and reallocates both the dring and the LDC channel including its map table - nothing to roll back, and the stale descriptor must not be touched.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux a11f6ca9aef989b56cd31ff4ee2af4fb31a172ec ~ eb9c5f6747fe98b83c78cb5476a914e91d50e8e8 -
Linux Linux 5.0 -

II. Public POCs for CVE-2026-97952

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97952

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97952 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97952

No comments yet


Leave a comment