VGA Arbiter Client Release Issue in Linux Kernel by Linux Foundation
CVE-2026-64475
What is CVE-2026-64475?
A vulnerability in the Linux Kernel's vfio/pci component was identified, where failure during the registration of the VGA arbiter client could lead to improper resource management. The issue stems from the re-ordering of the failure handling within the vfio_pci_core_register_device() function, which did not appropriately unwind on failure. Although this may seem relatively benign in contemporary kernel versions, the absence of an unwinding mechanism raises concerns regarding potential callbacks referencing previously freed device contexts. This flaw necessitates the implementation of a required unwind call for the VGA arbiter to maintain system integrity.
Affected Version(s)
Linux 87856f9af04eaacf9848710625a4ffee1d020fa9 < 0f2a35a0c7ea7da347b814750eaa78adf3582381
Linux 4aeec3984ddc853f7c65903bde472ffdef738bae < 8d65decde9afd2bd78bcfffdc0df73b82a0b5509
Linux 4aeec3984ddc853f7c65903bde472ffdef738bae