{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx  vhost_vdpa_set_config_call() swaps the eventfd_ctx_fdget() return value into v-\u003econfig_ctx before checking it, so on failure the field briefly holds an ERR_PTR:  \tctx = fd == VHOST_FILE_UNBIND ? NULL : eventfd_ctx_fdget(fd); \tswap(ctx, v-\u003econfig_ctx);  \tif (!IS_ERR_OR_NULL(ctx)) \t\teventfd_ctx_put(ctx);  \tif (IS_ERR(v-\u003econfig_ctx)) { \t\tlong ret = PTR_ERR(v-\u003econfig_ctx);  \t\tv-\u003econfig_ctx = NULL; \t\treturn ret; \t}  Commit 0bde59c1723a (\"vhost-vdpa: set v-\u003econfig_ctx to NULL if eventfd_ctx_fdget() fails\") added that clearing, and spelled out the invariant the rest of the file relies on: \"we consider 'v-\u003econfig_ctx' valid if it is not NULL\".  The window between the swap and the clearing still breaks it.  vhost_vdpa_config_cb() only tests for NULL, so a config interrupt delivered inside the window hands the ERR_PTR to eventfd_signal().  Check the fd before installing it instead.  That closes the window and matches how vhost_vring_ioctl() handles the same failure for the vq call fd.  It also stops a rejected fd from tearing down a config interrupt that was working: until now the swap replaced the live context and put it, so after an EBADF the device silently stopped delivering config interrupts until userspace installed a new fd.",
  "id": "DEBIAN-CVE-2026-97993",
  "modified": "2026-09-26T04:47:28.647044472Z",
  "published": "2026-09-25T11:17:27.500Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97993"
    }
  ],
  "upstream": [
    "CVE-2026-97993"
  ]
}