---
id: CVE-2026-97989
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vduse: validate virtqueue alignment

  vduse_validate_config() only checks the upper bound of vq_align
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vduse: validate virtqueue alignment

  vduse_validate_config() only checks the upper bound of vq_align. Invalid
  values can therefore reach vring_create_virtqueue_map(). T…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c8a6153b6c59d95c0e091f053f6f180952ade91e <
    c3c3b0839a1197530cc18f535062fc84dbdfc885
  - >-
    Linux >= c8a6153b6c59d95c0e091f053f6f180952ade91e <
    fa2c25b4add57888acfa89e398389e267bff3dcf
  - Linux 5.15
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:27.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97989'
references:
  - url: 'https://git.kernel.org/stable/c/c3c3b0839a1197530cc18f535062fc84dbdfc885'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fa2c25b4add57888acfa89e398389e267bff3dcf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.865Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

vduse: validate virtqueue alignment

vduse_validate_config() only checks the upper bound of vq_align. Invalid
values can therefore reach vring_create_virtqueue_map(). The split-ring
helpers use align - 1 as a bit mask, so the alignment must be a non-zero
power of two. A zero value makes vring_size() drop the descriptor and
available-ring part and vring_init() leave the used ring pointer NULL.

The VIRTIO spec requires the used ring to start at an address
aligned to at least 4 bytes. Reject values below VRING_USED_ALIGN_SIZE as
well as non-power-of-two values before they reach the virtio ring helpers.

Opening a virtio-net device created with vq_align=0 triggered:

BUG: KASAN: null-ptr-deref in virtqueue_kick_prepare_split+0xe3/0x100
Read of size 2 at addr 0000000000000000 by task systemd-network/1062

Call Trace (relevant frames):
 dump_stack_lvl
 print_report
 kasan_report
 __asan_load2
 virtqueue_kick_prepare_split+0xe3/0x100
 virtqueue_kick_prepare+0x40/0x60
 try_fill_recv+0x857/0x1250
 virtnet_open+0x189/0x460
 __dev_open+0x225/0x390
 __dev_change_flags+0x368/0x3b0
 netif_change_flags+0x56/0xc0
 do_setlink.isra.0+0x68c/0x1e30

Validate the value before it reaches the virtio ring helpers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
