GHSA-92f9-q54w-fxm8HighCVSS 7.3

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but...

Published
July 28, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.

🔗 References (5)