Junglewise Threat Intelligence

CVE-2026-74614: Linux kernel vsock/virtio race condition in worker locks

CVE-2026-74614 · Severity: high · CVSS 8.4 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's vsock (virtual socket) implementation used for inter-VM communication contains a race condition where worker threads can reference deleted virtqueue objects during device suspend/resume cycles. An attacker with access to a VM could trigger a use-after-free condition leading to kernel memory corruption, denial of service, or potential privilege escalation.

Technical details

The vulnerability is a use-after-free race condition in the virtio-based vsock transport layer (net/vmw_vsock/virtio_transport.c). When device suspend/resume operations introduce replacement virtqueues, the RX, TX, and event worker threads read their virtqueue pointer before acquiring the mutex and checking the corresponding run flag. A worker thread delayed across a freeze/restore cycle can observe the new queue's running state while holding a pointer to the deleted queue, resulting in a use-after-free access. The fix reorders operations to read the virtqueue pointer after acquiring the mutex and checking the run flag, ensuring the pointer and running state remain synchronized. The vulnerability affects systems with vsock enabled and can be exploited by unprivileged code to cause kernel crashes or potentially escalate privileges.

Affected products

  • Linux Linux kernel affected by bd50c5dc182b (vsock/virtio: add support for device suspend/resume) through at least 6.9.y before fix commit ebac8f6b1ef0e9278afe204b8692a7479988dace

Timeline

  • 2026-08-22: disclosed: CVE-2026-74614 published
  • 2026-08-19: patched: Fix commit ebac8f6b1ef0e9278afe204b8692a7479988dace merged to stable branches

References

Related threats