vsock/virtio: flush works in dependency order
Summary
| CVE | CVE-2026-80932 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:18:57 UTC |
| Updated | 2026-09-14 13:18:49 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for dependencies between those items: tx_work may queue send_pkt_work, and send_pkt_work may queue rx_work. In particular, send_pkt_work can set restart_rx and release tx_lock. The remove path can then stop the queues and flush rx_work before send_pkt_work queues it. Although the later send_pkt_work flush waits for that producer to finish, nothing waits for the newly queued rx_work, so kfree(vsock) can race with it. KASAN reported: BUG: KASAN: slab-use-after-free in virtio_transport_rx_work+0x487/0x4b0 Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtio_transport_rx_work+0x487/0x4b0 process_one_work+0x688/0x1120 worker_thread+0x45b/0xd10 Allocated by task 1: virtio_vsock_probe+0xef/0x6b0 Freed by task 84: kfree+0x131/0x3c0 virtio_vsock_remove+0xd1/0x100 Flush the works in producer-to-consumer order. virtio_vsock_vqs_del() has already disabled the queue callbacks and cleared the run flags, so after tx_work and send_pkt_work are drained, no source remains that can queue rx_work after its flush. |
Risk And Classification
Primary CVSS: v3.1 8.4 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001400000 probability, percentile 0.036590000 (date 2026-09-14)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.4 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 e059a14c1067bcc4f7b1947cd09f2baab98e340f git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 531e2ac2dab1ab90a16427c4f9c86663633e9487 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 f3313d952fc380cff53db9a28451a8807aa67b43 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 2187a56f2fd1715d54daed6392809223c60544f3 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 165a330a68b5f299d8735f0194c314cb2e571269 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 da5e9f08714c19ba04e6863aca69d40f042f2e04 git | Not specified |
| CNA | Linux | Linux | affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 728836ebca239810f164262b10211ef59182f811 git | Not specified |
| CNA | Linux | Linux | affected 4.8 | Not specified |
| CNA | Linux | Linux | unaffected 4.8 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.270 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.109 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.50 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.4 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.