Executive brief
A vulnerability in the Linux kernel's virtio transport mechanism could allow a malicious guest virtual machine to crash the host system. By advertising an extremely large communication buffer and reading data slowly, the guest can force the host to exhaust its available memory. This results in a denial-of-service condition where the host system may become unresponsive or trigger an Out-of-Memory (OOM) event.
Technical details
A resource exhaustion vulnerability exists in the Linux kernel's vsock/virtio transport (virtio_transport_common.c). The implementation derived TX credits directly from the peer's advertised buffer size (peer_buf_alloc) without intersecting it with the local buffer configuration (buf_alloc). A malicious local guest can advertise a massive buffer size via SO_VM_SOCKETS_BUFFER_SIZE and read data slowly, forcing the host to queue a large number of sk_buff structures in the kernel slab. This can lead to host memory exhaustion (SUnreclaim slab growth). The fix introduces virtio_transport_tx_buf_size() to cap the effective TX window to the minimum of the peer's advertised buffer and the local buffer limit.
Affected products
- Linux Linux Kernel Fixed in 84ef86aa, 8ee784fd, c0e42fb0, d9d5f222, fef7110a
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.6 and later
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later
Timeline
- 2026-01-21: patched: Initial patch authored
- 2026-02-04: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/84ef86aa7120449828d1e0ce438c499014839711
- https://git.kernel.org/stable/c/8ee784fdf006cbe8739cfa093f54d326cbf54037
- https://git.kernel.org/stable/c/c0e42fb0e054c2b2ec4ee80f48ccd256ae0227ce
- https://git.kernel.org/stable/c/d9d5f222558b42f6277eafaaa6080966faf37676
- https://git.kernel.org/stable/c/fef7110ae5617555c792a2bb4d27878d84583adf
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html