Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90384.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90384
Upstream
Published
2026-06-25T09:16:30Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-53132 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: fix potential unbounded skb queue

virtiotransportincrxpkt() checks vvs->rxbytes + len > vvs->bufalloc.

virtiotransportrecvenqueue() skips coalescing for packets with VIRTIOVSOCKSEQEOM.

If fed with packets with len == 0 and VIRTIOVSOCKSEQEOM, a very large number of packets can be queued because vvs->rxbytes stays at 0.

Fix this by estimating the skb metadata size:

(Number of skbs in the queue) * SKB_TRUESIZE(0)
References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90384.json"