SB20251230309 - Race condition in Linux kernel vdpa virtio_pci driver
Published: December 30, 2025
Security Bulletin ID
SB20251230309
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2022-50873)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition within the vp_vdpa_remove() function in drivers/vdpa/virtio_pci/vp_vdpa.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6ccc891f36d0c20ee220551caabdcd3886ec584b
- https://git.kernel.org/stable/c/8fe12680b2c731201519935013ec9219c93ec540
- https://git.kernel.org/stable/c/ed843d6ed7310a27cf7c8ee0a82a482eed0cb4a6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2