CVE-2026-13212: Virtio Unvalidated Used Ring Index

Virtio used-ring descriptor ID is used as an array index without bounds checking against the queue size. An untrusted virtio device or host backend can supply an out-of-bounds ID to trigger out-of-bounds access or control-flow hijacking. Validate that the descriptor ID is within queue bounds (e.g., id < vq->num).

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-13212-virtio-unvalidated-used-ring-index --engine opengrep

Description

Virtio used-ring descriptor ID is used as an array index without bounds checking against the queue size. An untrusted virtio device or host backend can supply an out-of-bounds ID to trigger out-of-bounds access or control-flow hijacking. Validate that the descriptor ID is within queue bounds (e.g., id < vq->num).