Improper input validation in Linux kernel - CVE-2026-97989
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in vduse_validate_config() when opening a virtio-net device created with a zero virtqueue alignment value. A local user can create and open a virtio-net device with an invalid virtqueue alignment value to cause a denial of service.