Re: [BUG] virtio_ring: VDUSE backend can corrupt split-ring free list
From: 성병찬
Date: Tue Oct 06 2026 - 05:39:35 EST
Yes, the backend causes the driver to corrupt its own virtqueue
free-list accounting.
My concern was that, after privileged VDUSE setup, a delegated
unprivileged backend can trigger this by modifying a published
descriptor. However, my current reproducer demonstrates duplicate
descriptor allocation only. It does not demonstrate a host
memory-safety violation, cross-device impact, information disclosure,
or privilege escalation.
I therefore agree that the current evidence supports a robustness
issue rather than a confirmed security vulnerability.
Would a patch using the driver-owned desc_extra flags during detach
still be considered worthwhile, or is protection against this backend
behavior outside the intended threat model?
Regards,
sungbyeongchan