Exposure of Resource to Wrong Sphere in Linux kernel - CVE-2026-98156
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to compromise confidentiality, integrity, and availability of memory belonging to another domain.
The vulnerability exists due to improper DMA address handling in virtio_gpu_object_shmem_init() when providing resource backing for a virtio-gpu framebuffer. A local user can cause framebuffer backing pages to be described with guest-physical addresses to compromise confidentiality, integrity, and availability of memory belonging to another domain.
Only Xen PV domains are affected; PVH domains are identity-mapped.