{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80932","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.802Z","datePublished":"2026-09-11T19:42:07.012Z","dateUpdated":"2026-09-14T11:58:59.006Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:58:59.006Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in the guest virtio-vsock driver during virtio_vsock_remove(), reached via virtio device unplug and AF_VSOCK virtqueue completions rather than routed packets; kernel CNA guidance scores vsock and virtio guest-driver bugs as Local.\nAC:L - A malicious hypervisor controls both sides of the race by injecting vsock packets that generate RST replies so send_pkt_work sets restart_rx and queues rx_work, while concurrently hot-unplugging the device so remove() flushes rx_work too early; the attacker can retry and pause guest vCPUs, so success is not an uncontrolled condition.\nPR:N - No guest privileges are required: a malicious hypervisor or deprivileged VMM (Firecracker, crosvm, TDX/SEV-SNP) triggers device removal and virtqueue traffic with no guest credentials; host-sent packets to unbound ports generate reply skbs in kernel workqueues without any guest socket, user, or capability.\nUI:N - virtio_vsock_remove() and the racing send_pkt_work/rx_work items run from driver teardown and virtqueue IRQ workqueues; no guest user must mount a filesystem, open a device, or take any other action.\nS:U - The use-after-free corrupts the guest kernel virtio_vsock object and remains within the guest OS security authority; a guest-to-host escape would require a host vhost-vsock bug, not this guest-side remove path.\nC:H - KASAN reports a slab use-after-free read in virtio_transport_rx_work of the kfree'd virtio_vsock; a workqueue callback running on a freed slab object enables attacker-controlled reuse and arbitrary kernel memory disclosure.\nI:H - After kfree(vsock), pending rx_work still runs against the freed object (rx_lock, vqs, flags); slab reuse of that work_struct yields arbitrary writes and control-flow hijack typical of kernel workqueue UAFs, not merely a crash.\nA:H - The reported KASAN bug is a kernel slab-use-after-free in virtio_transport_rx_work during device removal, causing oops or panic and fully denying guest availability even without completing a privilege-escalation exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/vmw_vsock/virtio_transport.c"],"versions":[{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"e059a14c1067bcc4f7b1947cd09f2baab98e340f","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"531e2ac2dab1ab90a16427c4f9c86663633e9487","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"f3313d952fc380cff53db9a28451a8807aa67b43","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"2187a56f2fd1715d54daed6392809223c60544f3","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"165a330a68b5f299d8735f0194c314cb2e571269","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"da5e9f08714c19ba04e6863aca69d40f042f2e04","status":"affected","versionType":"git"},{"version":"0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872","lessThan":"728836ebca239810f164262b10211ef59182f811","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/vmw_vsock/virtio_transport.c"],"versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.8","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f"},{"url":"https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487"},{"url":"https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43"},{"url":"https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94"},{"url":"https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3"},{"url":"https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269"},{"url":"https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04"},{"url":"https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811"}],"title":"vsock/virtio: flush works in dependency order","x_generator":{"engine":"bippy-1.2.0"}}}}