Race condition in Linux kernel - CVE-2026-97988

 

Race condition in Linux kernel - CVE-2026-97988

Published: September 28, 2026


Vulnerability identifier: #VU152493
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97988
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause stale ring mappings to be used.

The vulnerability exists due to improper synchronization of cached vring pointers and IOTLB metadata in vhost IOTLB handling when transitioning VIRTIO_F_ACCESS_PLATFORM. A local user can transition VIRTIO_F_ACCESS_PLATFORM settings to cause stale ring mappings to be used.


Affected software

Linux kernel

How to mitigate CVE-2026-97988

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins