๐Ÿ” CVE Alert

CVE-2026-80932

HIGH 8.4

vsock/virtio: flush works in dependency order

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for dependencies between those items: tx_work may queue send_pkt_work, and send_pkt_work may queue rx_work. In particular, send_pkt_work can set restart_rx and release tx_lock. The remove path can then stop the queues and flush rx_work before send_pkt_work queues it. Although the later send_pkt_work flush waits for that producer to finish, nothing waits for the newly queued rx_work, so kfree(vsock) can race with it. KASAN reported: BUG: KASAN: slab-use-after-free in virtio_transport_rx_work+0x487/0x4b0 Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtio_transport_rx_work+0x487/0x4b0 process_one_work+0x688/0x1120 worker_thread+0x45b/0xd10 Allocated by task 1: virtio_vsock_probe+0xef/0x6b0 Freed by task 84: kfree+0x131/0x3c0 virtio_vsock_remove+0xd1/0x100 Flush the works in producer-to-consumer order. virtio_vsock_vqs_del() has already disabled the queue callbacks and cleared the run flags, so after tx_work and send_pkt_work are drained, no source remains that can queue rx_work after its flush.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < e059a14c1067bcc4f7b1947cd09f2baab98e340f 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < 531e2ac2dab1ab90a16427c4f9c86663633e9487 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < f3313d952fc380cff53db9a28451a8807aa67b43 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < 2187a56f2fd1715d54daed6392809223c60544f3 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < 165a330a68b5f299d8735f0194c314cb2e571269 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < da5e9f08714c19ba04e6863aca69d40f042f2e04 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 < 728836ebca239810f164262b10211ef59182f811
Linux / Linux
4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f git.kernel.org: https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487 git.kernel.org: https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43 git.kernel.org: https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94 git.kernel.org: https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3 git.kernel.org: https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269 git.kernel.org: https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04 git.kernel.org: https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811