Yes, the backend causes the driver to corrupt its own virtqueue free-list accounting.
My concern was that, after privileged VDUSE setup, a delegated unprivileged backend can trigger this by modifying a published descriptor. However, my current reproducer demonstrates duplicate descriptor allocation only. It does not demonstrate a host memory-safety violation, cross-device impact, information disclosure, or privilege escalation. I therefore agree that the current evidence supports a robustness issue rather than a confirmed security vulnerability. Would a patch using the driver-owned desc_extra flags during detach still be considered worthwhile, or is protection against this backend behavior outside the intended threat model? Regards, sungbyeongchan

