CVE-2026-97983
In the Linux kernel, the following vulnerability has been resolved: vduse: return compat ioctl results directly The compat handler handles VDUSE_IOTLB_GET_FD and VDUSE_VQ_GET_INFO, but then calls the native handler. Their different command sizes make native dispatch return -ENOIOCTLCMD. For GET_FD, this overwrites receive_fd()'s return value after the descriptor is installed, leaking one fd per call. Return handled compat results directly and use native dispatch only for other commands.
Affected versions
Linux kernel versions
7.1.5,
7.2
and later are affected. Fixed in
7.2.7,
7.3-rc3
and their respective stable series.
References
2 totalFrequently asked questions
-
What is CVE-2026-97983?
CVE-2026-97983 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 7.1.5 onward and has been patched in 7.2.7 and 7.3-rc3. CVE-2026-97983 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-97983?
Yes. CVE-2026-97983 has been patched. Fixed versions include 7.2.7 and 7.3-rc3. If you are running Linux kernel 7.1.5 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-97983 actively exploited?
No. CVE-2026-97983 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.