Junglewise Threat Intelligence

CVE-2026-53132: Linux Kernel resource exhaustion in virtio-vsock transport

CVE-2026-53132 · Severity: info · CVSS 0 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization networking component (virtio-vsock) could allow a malicious guest or adjacent system to exhaust host memory. By sending a large volume of specially crafted empty network packets, an attacker can bypass memory limits and cause a system slowdown or crash. This affects environments using virtio-based virtual machines.

Technical details

A resource exhaustion vulnerability exists in net/vmw_vsock/virtio_transport_common.c within the Linux kernel. The virtio_transport_inc_rx_pkt() function failed to account for sk_buff (skb) metadata overhead when validating receive buffer limits. By sending zero-length packets with the VIRTIO_VSOCK_SEQ_EOM flag, an attacker prevents packet coalescing while keeping the reported byte count at zero, bypassing the buf_alloc limit. This allows an unbounded number of skbs to be queued, leading to kernel memory exhaustion. Patches introduce an overhead estimation based on SKB_TRUESIZE(0) multiplied by the queue length to properly enforce memory limits.

Affected products

  • Linux Linux Kernel 6.3 through 7.0.12

Timeline

  • 2026-04-30: patched: Initial fix authored by Eric Dumazet
  • 2026-06-25: disclosed: CVE-2026-53132 published via NVD

References

Related threats