CVE-2026-72306EPSS p10.7%
CVE-2026-72306CVE-2026-72306
Description
In the Linux kernel, the following vulnerability has been resolved:
vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter
There is one race case in vduse_dev_msg_sync and vduse_dev_read_iter:
vduse_dev_read_iter():
lock(msg_lock);
dequeue_msg(send_list);
unlock(msg_lock);
vduse_dev_msg_sync():
wait_timeout() finish
lock(msg_lock);
check msg->complete is false
list_del(msg); <- double list_del() crash!
To fix this case, we shall ensure vduse_msg is on send_list or recv_list
outside the msg_lock critical section.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.7% · 2026-10-04T12:00:21Z |
| Last modified | 2026-08-17 |