Impact
A race condition exists in the Linux virtio‑vsock implementation where the removal path stops virtqueues and flushes work items in an order that does not respect producer–consumer dependencies. This flaw can allow an independently queued work item to execute after a preceding one has been freed, leading to a slab use‑after‑free. The resulting memory corruption may cause a kernel panic or, in certain scenarios, enable an attacker to execute arbitrary code at kernel privilege. The weakness is classified as CWE‑364, a classic race condition that abuses the timing of producer and consumer tasks.
Affected Systems
All Linux kernel builds that contain the virtio‑vsock driver in the mainline source tree and that have not yet received the patch are affected. This includes mainstream distribution kernels that ship the upstream kernel without the recent virtio‑vsock fix. No exact version range is provided, so any kernel older than the commit that introduces the correct dependency order is at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of < 1 % indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, but the nature of the bug—a local race condition—means that a privileged or local attacker who can influence the environment may exploit it. Consequently, the risk remains enabled, especially for machines that run untrusted code or host open environments.
OpenCVE Enrichment
Debian DSA