Re: [BUG] virtio_ring: VDUSE backend can corrupt split-ring free list
From: Michael S. Tsirkin
Date: Tue Oct 06 2026 - 05:52:59 EST
On Tue, Oct 06, 2026 at 06:39:23PM +0900, 성병찬 wrote:
> Yes, the backend causes the driver to corrupt its own virtqueue
> free-list accounting.
>
> My concern was that, after privileged VDUSE setup, a delegated
> unprivileged backend can trigger this by modifying a published
> descriptor. However, my current reproducer demonstrates duplicate
> descriptor allocation only. It does not demonstrate a host
> memory-safety violation, cross-device impact, information disclosure,
> or privilege escalation.
>
> I therefore agree that the current evidence supports a robustness
> issue rather than a confirmed security vulnerability.
>
> Would a patch using the driver-owned desc_extra flags during detach
> still be considered worthwhile, or is protection against this backend
> behavior outside the intended threat model?
>
> Regards,
> sungbyeongchan
It's outside a threat model but if the rest of data is coming from
desc_extra I don't see a good reason to read flags from the descriptor.
Will likely be better for cache, too.