Kestrel
대시보드로 돌아가기
CVE-2026-97478UNKNOWNMITRENVD대응게시일: 2026. 09. 24.수정일: 2026. 09. 24.CNA: 416baaa9-dc9f-4396-8d5f-8c081fb06d67Received

In the Linux kernel, the following vulnerability has been resolved: virt: acrn: Fix irqfd use-after-free during eventfd shutdown acrn_irqf

위협 신호 · CVSS · EPSS · KEV

정기 패치· 높은 악용 신호 없음
CVSS
—unknown

이론적 심각도 점수

EPSS
—

예측 데이터 없음

KEV
미등재

실측 악용 기록 없음

권장 대응 기한60일 이내CISA SSVC 기준

계획된 패치 주기 내 조치(60일 이내)

외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출

CVSS 벡터 · 메트릭

CVSS 벡터 정보 없음

상세 설명

In the Linux kernel, the following vulnerability has been resolved:

virt: acrn: Fix irqfd use-after-free during eventfd shutdown

acrn_irqfd_deassign() and the eventfd EPOLLHUP wakeup can race and free
the same struct hsm_irqfd:

CPU0 CPU1


eventfd_release()
wake_up_poll(EPOLLHUP)
hsm_irqfd_wakeup()
queue_work(&irqfd->shutdown)
acrn_irqfd_deassign()
hsm_irqfd_shutdown()
list_del_init()
eventfd_ctx_remove_wait_queue()
eventfd_ctx_put()
kfree(irqfd)
hsm_irqfd_shutdown_work()
container_of(work, ..., shutdown)
irqfd->vm <-- use-after-free

The deassign path freed the irqfd while a shutdown work item was
already queued by EPOLLHUP (or vice versa), so the work item could
resurrect a dangling pointer through container_of().

Switch to the lifetime model used by KVM irqfds:

  • Deassign/deinit only deactivate the irqfd: remove it from vm->irqfds
    under irqfds_lock and queue the cleanup work.
  • hsm_irqfd_shutdown_work() becomes the sole owner that unhooks the
    eventfd waitqueue entry, drops the eventfd reference and frees the
    irqfd.
  • A new HSM_IRQFD_FLAG_SHUTDOWN bit guarded by test_and_set_bit()
    ensures the cleanup work is queued at most once, no matter how many
    of {EPOLLHUP, deassign, deinit} fire concurrently. This is safe to
    call from the waitqueue callback, which runs with wqh->lock held and
    IRQs disabled and therefore cannot take irqfds_lock.
  • acrn_irqfd_deassign() flushes vm->irqfd_wq before returning so the
    eventfd is fully detached on return. acrn_irqfd_deinit() deactivates
    every irqfd, flushes the workqueue and only then destroys it, so no
    path can queue_work() onto a torn-down workqueue.
  • acrn_irqfd_assign() now installs the eventfd waitqueue entry and
    publishes the irqfd to vm->irqfds under irqfds_lock, so the irqfd is
    never visible to deassign/deinit before its waitqueue entry is in
    place, and any EPOLLHUP that fires in the assign window queues
    cleanup work that blocks on irqfds_lock until publication is done.

AI 심층 분석

공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.