Critical Alert 1 Active Exploit Detected Today

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-90129NVD

Vulnerability Summary

In the Linux kernel, the following vulnerability has been resolved:

virtio_balloon: quiesce balloon work before device shutdown

Commit 8bd2fa086a04 ("virtio: break and reset virtio devices on
device_shutdown()") added a generic virtio bus .shutdown handler that
breaks and resets every virtio device during device_shutdown(), i.e. on
reboot and kexec.

virtio_balloon provides no .shutdown of its own, so that generic path
runs while the balloon's asynchronous work is still armed. Once the
device has been broken, virtqueue_add_inbuf() in
virtballoon_free_page_report() returns -EIO and trips its
WARN_ON_ONCE(). On a kernel booted with panic_on_warn that turns an
ordinary reboot, for example a kexec based upgrade, into a fatal panic
in the middle of device_shutdown(), so the machine never reaches the
new kernel.

Relaxing that single WARN_ON_ONCE() would only hide the symptom: the
inflate/deflate and OOM paths do not warn, they call
wait_event(vb->acked, ...) and would instead block forever on a broken
queue that can no longer complete. The device has to be quiesced, not
just kept quiet.

Add a .shutdown handler that quiesces the balloon via the shared
virtballoon_quiesce() helper while the device is still alive, and only
then breaks and resets it via virtio_device_shutdown(). Unlike
virtballoon_remove() the balloon workqueue is not destroyed, as shutdown
does not free the device and cancel_work_sync() together with stop_update
already prevent any further work from being queued.
Severity Level
UNKNOWN
Published Date
Sep 17, 2026
Last Modified
Sep 17, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.20%Probability
Root Weakness (CWE)
N/A

Affected & Patched Versions

Affected Versions
  • Linux Linux >= 8bd2fa086a04886798b505f28db4002525895203 and < 6dd28e32f4d81a0d57c732b9900de24184e60a7d
  • Linux Linux >= 8bd2fa086a04886798b505f28db4002525895203 and < bdef50a8226fc04899ef6815dd08a002247d47d5
  • Linux Linux >= 8bd2fa086a04886798b505f28db4002525895203 and < 7e17eef04600c399c7e0f5ce765da5cf9d40d8e1
  • Linux Linux >= aee42f3d57bfa37b2716df4584edeecf63b9df4c
  • Linux Linux >= 6.14.9 and < 6.15
  • Linux Linux >= 6.15
Patched Versions
  • Linux Linux 6dd28e32f4d81a0d57c732b9900de24184e60a7d
  • Linux Linux bdef50a8226fc04899ef6815dd08a002247d47d5
  • Linux Linux 7e17eef04600c399c7e0f5ce765da5cf9d40d8e1
  • Linux Linux 6.15
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.