Re: [BUG] virtio_ring: VDUSE backend can corrupt split-ring free list

From: 성병찬

Date: Tue Oct 06 2026 - 05:39:35 EST


Yes, the backend causes the driver to corrupt its own virtqueue
free-list accounting.

My concern was that, after privileged VDUSE setup, a delegated
unprivileged backend can trigger this by modifying a published
descriptor. However, my current reproducer demonstrates duplicate
descriptor allocation only. It does not demonstrate a host
memory-safety violation, cross-device impact, information disclosure,
or privilege escalation.

I therefore agree that the current evidence supports a robustness
issue rather than a confirmed security vulnerability.

Would a patch using the driver-owned desc_extra flags during detach
still be considered worthwhile, or is protection against this backend
behavior outside the intended threat model?

Regards,
sungbyeongchan