DMA API Vulnerability in Linux Kernel Affects Virtio-GPU for Xen PV Domains
CVE-2026-98156
What is CVE-2026-98156?
A vulnerability has been identified in the Linux kernel pertaining to the virtio-gpu in Xen PV domains. The issue arises when the DMA API is not appropriately utilized for resource backing, allowing the host to access incorrect memory pages from unrelated domains. This flawed behavior in virtio-gpu, combined with improper handling of guest-physical addresses, could lead to unauthorized memory disclosure. The vulnerability requires addressing in systems running Xen PV environments with specific kernel versions, emphasizing the need for security patches and updates.
Affected Version(s)
Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 93c557e947ef0040004b1ac6a1c1265d79a957e1
Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 455184dbe9652d01470d3c5cf5edd09a7a673a99
Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 6a736d2f9d0c6e6217fe7532bc4c50ceca71db78