Executive brief
A vulnerability exists in the Linux kernel's VMCI transport for virtual sockets (vsock), which is used for communication between virtual machines and their host. If a peer resets a connection during the initial handshake, the system may incorrectly manage memory, leading to a crash or potential instability. This could allow a malicious or malfunctioning virtual machine to disrupt the host system's operations.
Technical details
A use-after-free (UAF) vulnerability exists in net/vmw_vsock/vmci_transport.c within the Linux kernel. The function vmci_transport_recv_connecting_server() incorrectly returned a success code (err = 0) when receiving a peer RST packet during a handshake. This caused vmci_transport_recv_listen() to skip the necessary vsock_remove_pending() call, leaving a pending socket on the listener's list while its reference count was prematurely decremented. Subsequent execution of vsock_pending_work() would then attempt to clean up the already-freed socket object, resulting in a slab-use-after-free. The fix ensures that peer RST packets are treated as errors (-EINVAL), forcing synchronous removal of the pending socket.
Affected products
- Linux Linux Kernel d021c344051af91f42c5ba9fdedc176740cbd238 to 1e19f08552b90070ed18bafb1763c78297823af6
Timeline
- 2026-07-19: advisory: NVD publication date
- 2026-06-01: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/1dd531e28f61edd286edc486ab068f135b5ae1eb
- https://git.kernel.org/stable/c/1e19f08552b90070ed18bafb1763c78297823af6
- https://git.kernel.org/stable/c/440447699c681e26ed58e9c309cad718270a18b4
- https://git.kernel.org/stable/c/47e63077605c6c2aa45b3df9847a8cdc1f1f6ef9
- https://git.kernel.org/stable/c/99e22ddf4edb63dc8382bc028af928056d3450cf
- https://git.kernel.org/stable/c/9fe74e42914c851d68069713b7b917a9c33faf26
- https://git.kernel.org/stable/c/cc27e989a5dfdfcfc1cca7c3be27a0c7532b46cb