{"api_version":"1","generated_at":"2026-09-18T01:06:17+00:00","cve":"CVE-2026-80932","urls":{"html":"https://cve.report/CVE-2026-80932","api":"https://cve.report/api/cve/CVE-2026-80932.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80932","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80932"},"summary":{"title":"vsock/virtio: flush works in dependency order","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:18:57","updated_at":"2026-09-14 13:18:49"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.4","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269","name":"https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04","name":"https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487","name":"https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3","name":"https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f","name":"https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43","name":"https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811","name":"https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94","name":"https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80932","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80932","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 e059a14c1067bcc4f7b1947cd09f2baab98e340f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 531e2ac2dab1ab90a16427c4f9c86663633e9487 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 f3313d952fc380cff53db9a28451a8807aa67b43 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 2187a56f2fd1715d54daed6392809223c60544f3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 165a330a68b5f299d8735f0194c314cb2e571269 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 da5e9f08714c19ba04e6863aca69d40f042f2e04 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 728836ebca239810f164262b10211ef59182f811 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.8","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.8 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.109 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80932","cve":"CVE-2026-80932","epss":"0.001400000","percentile":"0.036590000","score_date":"2026-09-14","updated_at":"2026-09-15 00:00:42"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e059a14c1067bcc4f7b1947cd09f2baab98e340f","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"531e2ac2dab1ab90a16427c4f9c86663633e9487","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"f3313d952fc380cff53db9a28451a8807aa67b43","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"2187a56f2fd1715d54daed6392809223c60544f3","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"165a330a68b5f299d8735f0194c314cb2e571269","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"da5e9f08714c19ba04e6863aca69d40f042f2e04","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"},{"lessThan":"728836ebca239810f164262b10211ef59182f811","status":"affected","version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/vmw_vsock/virtio_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.8"},{"lessThan":"4.8","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.109","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"4.8","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.8","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush."}],"metrics":[{"cvssV3_1":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in the guest virtio-vsock driver during virtio_vsock_remove(), reached via virtio device unplug and AF_VSOCK virtqueue completions rather than routed packets; kernel CNA guidance scores vsock and virtio guest-driver bugs as Local.\nAC:L - A malicious hypervisor controls both sides of the race by injecting vsock packets that generate RST replies so send_pkt_work sets restart_rx and queues rx_work, while concurrently hot-unplugging the device so remove() flushes rx_work too early; the attacker can retry and pause guest vCPUs, so success is not an uncontrolled condition.\nPR:N - No guest privileges are required: a malicious hypervisor or deprivileged VMM (Firecracker, crosvm, TDX/SEV-SNP) triggers device removal and virtqueue traffic with no guest credentials; host-sent packets to unbound ports generate reply skbs in kernel workqueues without any guest socket, user, or capability.\nUI:N - virtio_vsock_remove() and the racing send_pkt_work/rx_work items run from driver teardown and virtqueue IRQ workqueues; no guest user must mount a filesystem, open a device, or take any other action.\nS:U - The use-after-free corrupts the guest kernel virtio_vsock object and remains within the guest OS security authority; a guest-to-host escape would require a host vhost-vsock bug, not this guest-side remove path.\nC:H - KASAN reports a slab use-after-free read in virtio_transport_rx_work of the kfree'd virtio_vsock; a workqueue callback running on a freed slab object enables attacker-controlled reuse and arbitrary kernel memory disclosure.\nI:H - After kfree(vsock), pending rx_work still runs against the freed object (rx_lock, vqs, flags); slab reuse of that work_struct yields arbitrary writes and control-flow hijack typical of kernel workqueue UAFs, not merely a crash.\nA:H - The reported KASAN bug is a kernel slab-use-after-free in virtio_transport_rx_work during device removal, causing oops or panic and fully denying guest availability even without completing a privilege-escalation exploit."}]}],"providerMetadata":{"dateUpdated":"2026-09-14T11:58:59.006Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f"},{"url":"https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487"},{"url":"https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43"},{"url":"https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94"},{"url":"https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3"},{"url":"https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269"},{"url":"https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04"},{"url":"https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811"}],"title":"vsock/virtio: flush works in dependency order","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80932","datePublished":"2026-09-11T19:42:07.012Z","dateReserved":"2026-08-26T14:34:25.802Z","dateUpdated":"2026-09-14T11:58:59.006Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:18:57","lastModifiedDate":"2026-09-14 13:18:49","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80932","Ordinal":"1","Title":"vsock/virtio: flush works in dependency order","CVE":"CVE-2026-80932","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80932","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush.","Type":"Description","Title":"vsock/virtio: flush works in dependency order"}]}}}