vsock/virtio: avoid refilling the RX queue after teardown
Summary
| CVE | CVE-2026-74613 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-22 16:16:33 UTC |
| Updated | 2026-08-22 16:16:33 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: avoid refilling the RX queue after teardown
Commit b917507e5ad9 ("vsock/virtio: stop workers during the .remove()")
made the RX worker jump to its common exit when rx_run is clear. That
exit still refills the RX queue when the buffer count is low, so work
queued across virtio_vsock_vqs_del() can add buffers after the virtqueues
have been deleted.
BUG: KASAN: slab-use-after-free in virtqueue_add_sgs
Read of size 4 by task kworker/0:1
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
virtqueue_add_sgs (drivers/virtio/virtio_ring.c:2796)
virtio_vsock_rx_fill (net/vmw_vsock/virtio_transport.c:332)
virtio_transport_rx_work (net/vmw_vsock/virtio_transport.c:701)
process_one_work (kernel/workqueue.c:3314)
worker_thread (kernel/workqueue.c:3478)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
...
Freed by task 141:
kfree (mm/slub.c:6566)
vp_del_vq (drivers/virtio/virtio_pci_common.c:259)
vp_del_vqs (drivers/virtio/virtio_pci_common.c:285)
virtio_vsock_freeze (net/vmw_vsock/virtio_transport.c:912)
virtio_device_freeze (drivers/virtio/virtio.c:658)
virtio_pci_freeze (drivers/virtio/virtio_pci_common.c:601)
pci_pm_freeze (drivers/pci/pci-driver.c:1098)
device_suspend (drivers/base/power/main.c:1968)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
Jump to a no-refill exit when rx_run is clear, leaving the normal exit
to replenish a running queue. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 a7658508f5fe8f1077a65e8cb9535d3426f37a2f git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171 git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 4d37e3525cc346a1421c1bdeaad5848e249fc60c git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 9d80a04129a6c27a690cb69de3fe3f50be5aa8b9 git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 a309b74e3fc052352ab778500449cb9c3853c363 git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 38c7763fdc533edb34dc8f4489c260e8ba2ccae9 git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 e82a5faea2e3886dfb2a65ce092a132e7e896915 git |
Not specified |
| CNA |
Linux |
Linux |
affected b917507e5ad983085d29069369778b16aa03a0a8 a31e0ad444698d8aa7534a0f89fda543730f97a5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.3 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.3 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.265 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.216 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.152 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.104 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.45 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.9 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e82a5faea2e3886dfb2a65ce092a132e7e896915 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9d80a04129a6c27a690cb69de3fe3f50be5aa8b9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/38c7763fdc533edb34dc8f4489c260e8ba2ccae9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1aa21e7c8702a7c37cd7d3cace1a652cfa5e8171 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a7658508f5fe8f1077a65e8cb9535d3426f37a2f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a31e0ad444698d8aa7534a0f89fda543730f97a5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a309b74e3fc052352ab778500449cb9c3853c363 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/4d37e3525cc346a1421c1bdeaad5848e249fc60c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.