CVE-2026-80693
In the Linux kernel, the following vulnerability has been resolved:
idpf: bound interrupt-vector register fill to the allocated array
idpfgetregintrvecs() fills the caller-allocated reg_vals[] array from
the VIRTCHNL2OPALLOCVECTORS reply in adapter->reqvec_chunks, bounding
its inner loop only by the per-chunk num_vectors. The array is sized
separately: idpfintrreg_init() allocates
kzallocobjs(struct idpfvecregs, totalvecs) from
caps.numallocatedvectors and only checks the returned count after the
fill. The sum of per-chunk num_vectors is never reconciled against
totalvecs, so a reply with a small numallocated_vectors but chunks
summing higher writes past the end of reg_vals[].
Impact: a control plane (a PF or hypervisor device model) that returns a
VIRTCHNL2OPALLOCVECTORS reply whose per-chunk numvectors sum exceeds
numallocatedvectors writes struct idpfvecregs entries past the end of
the reg_vals kmalloc allocation (KASAN slab-out-of-bounds write).
Bound the fill loop to the array capacity passed in by the callers,
mirroring the sibling idpfvportgetqreg(). The existing
numregs < numvecs check then rejects an undersized reply without the
out-of-bounds write happening first.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/41bb8748124d0d8ee5d8e1eace9dfbc874bc9564, https://git.kernel.org/stable/c/9f7007ee9858c99aa43101bc8352c672fee85644, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80693.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80693, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git