Description
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual descriptor count is much larger than the expected limit. VIOSockSelectCopyFds then iterates using the unchecked count and writes beyond the allocated pPkt->Fds array in the NonPagedPool kernel heap. Successful exploitation can corrupt kernel memory and enable privilege escalation in a Windows guest running the driver. This issue is fixed in mm320.
Published: 2026-09-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability exists in the virtio-win viosock.sys driver used in Windows paravirtualized guests for QEMU and KVM. From release mm210 until mm320, a local low‑privilege process can submit an IOCTL_SELECT request with attacker‑controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32‑bit sum used by VIOSockSelect for bounds checking. The summed value can pass the FD_SETSIZE check even though an individual descriptor count is much larger than expected, allowing VIOSockSelectCopyFds to iterate using the unchecked count and write beyond the allocated pPkt->Fds array in the NonPagedPool kernel heap. This heap overflow can corrupt kernel memory and enable privilege escalation in the Windows guest.

Affected Systems

The vulnerability affects Windows systems that load the virtio-win viosock.sys driver. It applies to device versions from mm210 up to, but not including, mm320, the release that contains the fix. Any virtual machine using these earlier virtio-win driver releases therefore runs at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high impact vulnerability. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog, suggesting moderate but not high exploitation probability at present. Exploitation requires a low‑integrity process to issue the crafted IOCTL, so the attack vector is local. If leveraged successfully, the integer overflow could be used to overwrite kernel memory and execute arbitrary code, resulting in complete privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 12:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest virtio-win driver update that fixes the integer overflow in viosock.sys.
  • Enforce stricter access control for low‑integrity processes so they cannot issue IOCTL requests to viosock.sys, for example by using AppLocker or device‑driver access policies.
  • Monitor system logs for abnormal viosock.sys activity and maintain up‑to‑date monitoring rules to detect potential exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 12:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in virtio-win. A low-integrity process can issue an IOCTL request to viosock.sys!VIOSockSelect with a maliciously crafted request that causes an integer overflow. This allows the process to circumvent bounds checking, resulting in a heap overflow in the NonPagedPool kernel heap. The flaw could be exploited to escalate privileges on Windows systems running this driver. virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual descriptor count is much larger than the expected limit. VIOSockSelectCopyFds then iterates using the unchecked count and writes beyond the allocated pPkt->Fds array in the NonPagedPool kernel heap. Successful exploitation can corrupt kernel memory and enable privilege escalation in a Windows guest running the driver. This issue is fixed in mm320.
Title virtio-win: viosock.sys: integer overflow in VIOSockSelect leads to heap-based buffer overflow virtio-win: Integer overflow causing a heap overflow in Viosock driver
Weaknesses CWE-122
References

Wed, 24 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Virtio-win
Virtio-win kvm-guest-drivers-windows
Vendors & Products Virtio-win
Virtio-win kvm-guest-drivers-windows

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in virtio-win. A low-integrity process can issue an IOCTL request to viosock.sys!VIOSockSelect with a maliciously crafted request that causes an integer overflow. This allows the process to circumvent bounds checking, resulting in a heap overflow in the NonPagedPool kernel heap. The flaw could be exploited to escalate privileges on Windows systems running this driver.
Title virtio-win: viosock.sys: integer overflow in VIOSockSelect leads to heap-based buffer overflow
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

Virtio-win Kvm-guest-drivers-windows
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:15:05.093Z

Reserved: 2026-05-15T20:11:54.585Z

Link: CVE-2026-46655

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T17:16:57.373

Modified: 2026-09-23T20:17:10.863

Link: CVE-2026-46655

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-16T00:00:00Z

Links: CVE-2026-46655 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:00:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound