The EVTCHNOP_expand_array hypercall checks for whether...
High severity
Unreviewed
Published
Jul 28, 2026
to the GitHub Advisory Database
•
Updated Jul 28, 2026
Description
Published by the National Vulnerability Database
Jul 28, 2026
Published to the GitHub Advisory Database
Jul 28, 2026
Last updated
Jul 28, 2026
The EVTCHNOP_expand_array hypercall checks for whether FIFO event
channels are enabled, but without holding the correct lock. It can race
with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
References