CVE-2026-80932

Source
https://cve.org/CVERecord?id=CVE-2026-80932
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80932.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80932
Downstream
Published
2026-09-11T19:42:07Z
Modified
2026-09-13T03:46:48Z
Summary
vsock/virtio: flush works in dependency order
Details

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: flush works in dependency order

virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for dependencies between those items: tx_work may queue send_pkt_work, and send_pkt_work may queue rx_work.

In particular, send_pkt_work can set restart_rx and release tx_lock. The remove path can then stop the queues and flush rx_work before send_pkt_work queues it. Although the later send_pkt_work flush waits for that producer to finish, nothing waits for the newly queued rx_work, so kfree(vsock) can race with it.

KASAN reported:

BUG: KASAN: slab-use-after-free in virtio_transport_rx_work+0x487/0x4b0 Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtio_transport_rx_work+0x487/0x4b0 process_one_work+0x688/0x1120 worker_thread+0x45b/0xd10 Allocated by task 1: virtio_vsock_probe+0xef/0x6b0 Freed by task 84: kfree+0x131/0x3c0 virtio_vsock_remove+0xd1/0x100

Flush the works in producer-to-consumer order. virtio_vsock_vqs_del() has already disabled the queue callbacks and cleared the run flags, so after tx_work and send_pkt_work are drained, no source remains that can queue rx_work after its flush.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80932.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872
Fixed
2187a56f2fd1715d54daed6392809223c60544f3
Fixed
165a330a68b5f299d8735f0194c314cb2e571269
Fixed
da5e9f08714c19ba04e6863aca69d40f042f2e04
Fixed
728836ebca239810f164262b10211ef59182f811

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80932.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80932.json"