vhost-scsi: protect vq->log_used with vq->mutex
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: protect vq->log_used with vq->mutex The vhost-scsi completion path may access vq->log_base when vq->log_used is already set to false. vhost-thread QEMU-thread vhost_scsi_complete_cmd_work() -> vhost_add_used() -> vhost_add_used_n() if (unlikely(vq->log_used)) QEMU disables vq->log_used via VHOST_SET_VRING_ADDR. mutex_lock(&vq->mutex); vq->log_used = false now! mutex_unlock(&vq->mutex); QEMU gfree(vq->log_base) log_used() -> log_write(vq->log_base) Assuming the VMM is QEMU. The vq->log_base is from QEMU userpace and can be reclaimed via gfree(). As a result, this causes invalid memory writes to QEMU userspace. The control queue path has the same issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-38074
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/80cf68489681c165ded460930e391b1eb37b5f6f
- https://git.kernel.org/stable/c/8312a1ccff1566f375191a89b9ba71b6eb48a8cd
- https://git.kernel.org/stable/c/59614c5acf6688f7af3c245d359082c0e9e53117
- https://git.kernel.org/stable/c/ca85c2d0db5f8309832be45858b960d933c2131c
- https://git.kernel.org/stable/c/bd8c9404e44adb9f6219c09b3409a61ab7ce3427
- https://git.kernel.org/stable/c/c0039e3afda29be469d29b3013d7f9bdee136834
- https://git.kernel.org/stable/c/f591cf9fce724e5075cc67488c43c6e39e8cbe27
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.