---
id: CVE-2026-97993
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx

  vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value
  into v->config_ctx before…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx

  vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value
  into v->config_ctx before…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 776f395004d829bbbf18c159ed9beb517a208c71 <
    388c678639a0cebfd936b3e56c64ac6a371efec2
  - >-
    Linux >= 776f395004d829bbbf18c159ed9beb517a208c71 <
    65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a
  - >-
    Linux >= 776f395004d829bbbf18c159ed9beb517a208c71 <
    6b20b40f020bde236f6b8a08ff88d8653261ec2b
  - >-
    Linux >= 776f395004d829bbbf18c159ed9beb517a208c71 <
    e74a9fa50749b9940b4fb13199652325e08d3c4a
  - Linux 5.8
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:27.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97993'
references:
  - url: 'https://git.kernel.org/stable/c/388c678639a0cebfd936b3e56c64ac6a371efec2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/65faf9eaa00e408e1406fbcf675c8c8d0e27ff2a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6b20b40f020bde236f6b8a08ff88d8653261ec2b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e74a9fa50749b9940b4fb13199652325e08d3c4a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.864Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx

vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value
into v->config_ctx before checking it, so on failure the field briefly
holds an ERR_PTR:

	ctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd);
	swap(ctx, v->config_ctx);

	if (!IS_ERR_OR_NULL(ctx))
		eventfd_ctx_put(ctx);

	if (IS_ERR(v->config_ctx)) {
		long ret = PTR_ERR(v->config_ctx);

		v->config_ctx = NULL;
		return ret;
	}

Commit 0bde59c1723a ("vhost-vdpa: set v->config_ctx to NULL if
eventfd_ctx_fdget() fails") added that clearing, and spelled out the
invariant the rest of the file relies on: "we consider 'v->config_ctx'
valid if it is not NULL".  The window between the swap and the clearing
still breaks it.  vhost_vdpa_config_cb() only tests for NULL, so a config
interrupt delivered inside the window hands the ERR_PTR to
eventfd_signal().

Check the fd before installing it instead.  That closes the window and
matches how vhost_vring_ioctl() handles the same failure for the vq call
fd.

It also stops a rejected fd from tearing down a config interrupt that was
working: until now the swap replaced the live context and put it, so
after an EBADF the device silently stopped delivering config interrupts
until userspace installed a new fd.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
