[SRU][N/J][PATCH 0/2] CVE-2025-38064

Cengiz Can cengiz.can at canonical.com
Thu Sep 10 10:07:56 UTC 2026


https://ubuntu.com/security/CVE-2025-38064

[ Impact ]

In the Linux kernel, the following vulnerability has been resolved:

virtio: break and reset virtio devices on device_shutdown()

Hongyu reported a hang on kexec in a VM. QEMU reported invalid memory accesses
during the hang.

Invalid read at addr 0x102877002, size 2, region '(null)', reason: rejected
Invalid write at addr 0x102877A44, size 2, region '(null)', reason: rejected
...

It was traced down to virtio-console. Kexec works fine if virtio-console is not
in use.

The issue is that virtio-console continues to write to the MMIO even after
underlying virtio-pci device is reset.

Additionally, Eric noticed that IOMMUs are reset before devices, if devices are
not reset on shutdown they continue to poke at guest memory and get errors from
the IOMMU. Some devices get wedged then.

The problem can be solved by breaking all virtio devices on virtio bus
shutdown, then resetting them.

[ Fix ]

noble/linux: backported from 8bd2fa086a04
jammy/linux: backported from 8bd2fa086a04

[ Test Plan ]

Build and boot tested.

[ Where Problems Could Occur ]

This change adds a shutdown handler to the virtio bus that breaks and resets
every virtio device when the system shuts down, reboots or performs a kexec.
A bad fix would therefore most likely surface on virtualized guests that use
virtio devices such as virtio-console, virtio-blk, virtio-net or virtio-scsi,
potentially as hangs or data loss during shutdown, reboot or kexec. Bare-metal
systems and guests that do not use any virtio devices are not affected.

[ Other Info ]

Kybele flow-v11-25-ga27c0fa6. Reference: 4c28d7a4/v1



More information about the kernel-team mailing list