๐Ÿ” CVE Alert

CVE-2026-45890

UNKNOWN 0.0

xen-netback: reject zero-queue configuration from guest

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xen-netback: reject zero-queue configuration from guest A malicious or buggy Xen guest can write "0" to the xenbus key "multi-queue-num-queues". The connect() function in the backend only validates the upper bound (requested_num_queues > xenvif_max_queues) but not zero, allowing requested_num_queues=0 to reach vzalloc(array_size(0, sizeof(struct xenvif_queue))), which triggers WARN_ON_ONCE(!size) in __vmalloc_node_range(). On systems with panic_on_warn=1, this allows a guest-to-host denial of service. The Xen network interface specification requires the queue count to be "greater than zero". Add a zero check to match the validation already present in xen-blkback, which has included this guard since its multi-queue support was added.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 27, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < 2993e0f904c45f8af12917344bb1cac7ccd05a60 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < 787bfa423228c4b02ba3368128f625d579085353 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < ce66d6786de45b7ed9cbbdc0988054bf09e58f54 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < 88b0fced1bbbfdb356a007592604008ffc93a6a1 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < ec4859ac5c933e3315543a61adc1ca4358006a41 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < 654780dee9eae419e1648ea58462c4efe54518fa 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < d99f69ddc70fd9f4b8148add62209a1a8eb5c615 8d3d53b3e43363e79ab9a9ecc149b06c1314b25d < 6d1dc8014334c7fb25719999bca84d811e60a559
Linux / Linux
3.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60 git.kernel.org: https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353 git.kernel.org: https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54 git.kernel.org: https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1 git.kernel.org: https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41 git.kernel.org: https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa git.kernel.org: https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615 git.kernel.org: https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559