7.8

CVE-2026-74613

vsock/virtio: avoid refilling the RX queue after teardown

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: avoid refilling the RX queue after teardown

Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear.  That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.

BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
Read of size 4 by task kworker/0:1
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
 virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
 virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
 virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
 process_one_work (kernel/workqueue.c:3314)
 worker_thread (kernel/workqueue.c:3478)
 kthread (kernel/kthread.c:436)
 ret_from_fork (arch/x86/kernel/process.c:158)
 ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Freed by task 141:
 kfree (mm/slub.c:6566)
 vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
 vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
 virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
 virtio_device_freeze (drivers/virtio/virtio.c:658)
 virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
 pci_pm_freeze (drivers/pci/pci-driver.c:1098)
 device_suspend (drivers/base/power/main.c:1968)
Kernel panic - not syncing: KASAN: panic_on_warn set ...

Jump to a no-refill exit when rx_run is clear, leaving the normal exit
to replenish a running queue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < a7658508f5fe8f1077a65e8cb9535d3426f37a2f
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < 1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < 4d37e3525cc346a1421c1bdeaad5848e249fc60c
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < 9d80a04129a6c27a690cb69de3fe3f50be5aa8b9
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < a309b74e3fc052352ab778500449cb9c3853c363
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < 38c7763fdc533edb34dc8f4489c260e8ba2ccae9
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < e82a5faea2e3886dfb2a65ce092a132e7e896915
Status affected
Version b917507e5ad983085d29069369778b16aa03a0a8
Version < a31e0ad444698d8aa7534a0f89fda543730f97a5
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.152
Status unaffected
Version <= 6.12.*
Version 6.12.104
Status unaffected
Version <= 6.18.*
Version 6.18.45
Status unaffected
Version <= 7.1.*
Version 7.1.9
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.072
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171
https://git.kernel.org/stable/c/38c7763fdc533edb34dc8f4489c260e8ba2ccae9
https://git.kernel.org/stable/c/4d37e3525cc346a1421c1bdeaad5848e249fc60c
https://git.kernel.org/stable/c/9d80a04129a6c27a690cb69de3fe3f50be5aa8b9
https://git.kernel.org/stable/c/a309b74e3fc052352ab778500449cb9c3853c363
https://git.kernel.org/stable/c/a31e0ad444698d8aa7534a0f89fda543730f97a5
https://git.kernel.org/stable/c/a7658508f5fe8f1077a65e8cb9535d3426f37a2f
https://git.kernel.org/stable/c/e82a5faea2e3886dfb2a65ce092a132e7e896915