CVE-2026-45890 Details
Description
In the Linux kernel, the following vulnerability has been resolved: xen-netback: reject zero-queue configuration from guest A malicious or buggy Xen guest can write "0" to the xenbus key "multi-queue-num-queues". The connect() function in the backend only validates the upper bound (requested_num_queues > xenvif_max_queues) but not zero, allowing requested_num_queues=0 to reach vzalloc(array_size(0, sizeof(struct xenvif_queue))), which triggers WARN_ON_ONCE(!size) in __vmalloc_node_range(). On systems with panic_on_warn=1, this allows a guest-to-host denial of service. The Xen network interface specification requires the queue count to be "greater than zero". Add a zero check to match the validation already present in xen-blkback, which has included this guard since its multi-queue support was added.
A vulnerability in the Linux kernel's Xen netback driver allows a malicious or faulty Xen guest to set the queue count to zero, bypassing validation checks. This misconfiguration can cause memory allocation functions to fail, triggering warnings that may lead to a guest-to-host denial-of-service condition, especially on systems configured to panic on such warnings. The issue arises because the Xen network interface specification mandates a queue count greater than zero, and the netback driver's validation only checks for upper limits, not for zero values.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2993e0f904c45f8af12917344bb1cac7ccd05a60 | kernel.org | Patch |
| https://git.kernel.org/stable/c/654780dee9eae419e1648ea58462c4efe54518fa | kernel.org | Patch |
| https://git.kernel.org/stable/c/6d1dc8014334c7fb25719999bca84d811e60a559 | kernel.org | Patch |
| https://git.kernel.org/stable/c/787bfa423228c4b02ba3368128f625d579085353 | kernel.org | Patch |
| https://git.kernel.org/stable/c/88b0fced1bbbfdb356a007592604008ffc93a6a1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ce66d6786de45b7ed9cbbdc0988054bf09e58f54 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d99f69ddc70fd9f4b8148add62209a1a8eb5c615 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ec4859ac5c933e3315543a61adc1ca4358006a41 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.16, < 5.10.252 >= 5.11, < 5.15.202 >= 5.16, < 6.1.165 >= 6.2, < 6.6.128 >= 6.7, < 6.12.75 >= 6.13, < 6.18.14 >= 6.19, < 6.19.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |