Description
In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: flush works in dependency order

virtio_vsock_remove() stops the virtqueues and then flushes each work
item before freeing the enclosing virtio_vsock. The current order does
not account for dependencies between those items: tx_work may queue
send_pkt_work, and send_pkt_work may queue rx_work.

In particular, send_pkt_work can set restart_rx and release tx_lock.
The remove path can then stop the queues and flush rx_work before
send_pkt_work queues it. Although the later send_pkt_work flush waits
for that producer to finish, nothing waits for the newly queued rx_work,
so kfree(vsock) can race with it.

KASAN reported:

BUG: KASAN: slab-use-after-free in
virtio_transport_rx_work+0x487/0x4b0
Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47
Workqueue: virtio_vsock virtio_transport_rx_work
Call Trace:
virtio_transport_rx_work+0x487/0x4b0
process_one_work+0x688/0x1120
worker_thread+0x45b/0xd10
Allocated by task 1:
virtio_vsock_probe+0xef/0x6b0
Freed by task 84:
kfree+0x131/0x3c0
virtio_vsock_remove+0xd1/0x100

Flush the works in producer-to-consumer order. virtio_vsock_vqs_del()
has already disabled the queue callbacks and cleared the run flags, so
after tx_work and send_pkt_work are drained, no source remains that can
queue rx_work after its flush.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Use-After-Free
Action: Apply Patch
AI Analysis

Impact

A race condition exists in the Linux virtio‑vsock implementation where the removal path stops virtqueues and flushes work items in an order that does not respect producer–consumer dependencies. This flaw can allow an independently queued work item to execute after a preceding one has been freed, leading to a slab use‑after‑free. The resulting memory corruption may cause a kernel panic or, in certain scenarios, enable an attacker to execute arbitrary code at kernel privilege. The weakness is classified as CWE‑364, a classic race condition that abuses the timing of producer and consumer tasks.

Affected Systems

All Linux kernel builds that contain the virtio‑vsock driver in the mainline source tree and that have not yet received the patch are affected. This includes mainstream distribution kernels that ship the upstream kernel without the recent virtio‑vsock fix. No exact version range is provided, so any kernel older than the commit that introduces the correct dependency order is at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, and the EPSS score of < 1 % indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV, but the nature of the bug—a local race condition—means that a privileged or local attacker who can influence the environment may exploit it. Consequently, the risk remains enabled, especially for machines that run untrusted code or host open environments.

Generated by OpenCVE AI on September 21, 2026 at 03:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel update that includes the virtio‑vsock work flush fix applied in commit 165a330a68b5
  • Restart any services that depend on virtio‑vsock to ensure the new kernel module is loaded
  • If a kernel upgrade cannot be performed immediately, disable or remove the virtio‑vsock driver to eliminate the vulnerability, for example by unloading the module or removing its configuration from system files

Generated by OpenCVE AI on September 21, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for dependencies between those items: tx_work may queue send_pkt_work, and send_pkt_work may queue rx_work. In particular, send_pkt_work can set restart_rx and release tx_lock. The remove path can then stop the queues and flush rx_work before send_pkt_work queues it. Although the later send_pkt_work flush waits for that producer to finish, nothing waits for the newly queued rx_work, so kfree(vsock) can race with it. KASAN reported: BUG: KASAN: slab-use-after-free in virtio_transport_rx_work+0x487/0x4b0 Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtio_transport_rx_work+0x487/0x4b0 process_one_work+0x688/0x1120 worker_thread+0x45b/0xd10 Allocated by task 1: virtio_vsock_probe+0xef/0x6b0 Freed by task 84: kfree+0x131/0x3c0 virtio_vsock_remove+0xd1/0x100 Flush the works in producer-to-consumer order. virtio_vsock_vqs_del() has already disabled the queue callbacks and cleared the run flags, so after tx_work and send_pkt_work are drained, no source remains that can queue rx_work after its flush.
Title vsock/virtio: flush works in dependency order
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:58:59.006Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:57.023

Modified: 2026-09-14T13:18:49.483

Link: CVE-2026-80932

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:07Z

Links: CVE-2026-80932 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-364

    Signal Handler Race Condition