DMA API Vulnerability in Linux Kernel Affects Virtio-GPU for Xen PV Domains
CVE-2026-98156

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98156?

A vulnerability has been identified in the Linux kernel pertaining to the virtio-gpu in Xen PV domains. The issue arises when the DMA API is not appropriately utilized for resource backing, allowing the host to access incorrect memory pages from unrelated domains. This flawed behavior in virtio-gpu, combined with improper handling of guest-physical addresses, could lead to unauthorized memory disclosure. The vulnerability requires addressing in systems running Xen PV environments with specific kernel versions, emphasizing the need for security patches and updates.

Affected Version(s)

Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 93c557e947ef0040004b1ac6a1c1265d79a957e1

Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 455184dbe9652d01470d3c5cf5edd09a7a673a99

Linux a3b815f09bb846255c458c181b8a5b1cc66891b4 < 6a736d2f9d0c6e6217fe7532bc4c50ceca71db78

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.