CVE-2026-80932
CVE CVE-2026-80932EUVD EUVD-2026-76255Veröffentlicht 2026-09-11T19:42:07.000ZZuletzt geändert 2026-09-14T11:58:59.000ZCVSS 8.4
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtio_vsock_remove() stops the virtqueues and then flushes each work item before freeing the enclosing virtio_vsock. The current order does not account for dependencies between those items: tx_work may queue send_pkt_work, and send_pkt_work may queue rx_work. In particular, send_pkt_work can set restart_rx and release tx_lock. The remove path can then stop the queues and flush rx_work before send_pkt_work queues it. Although the later send_pkt_work flush waits for that producer to finish, nothing waits for the newly queued rx_work, so kfree(vsock) can race with it. KASAN reported: BUG: KASAN: slab-use-after-free in virtio_transport_rx_work+0x487/0x4b0 Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47 Workqueue: virtio_vsock virtio_transport_rx_work Call Trace: virtio_transport_rx_work+0x487/0x4b0 process_one_work+0x688/0x1120 worker_thread+0x45b/0xd10 Allocated by task 1: virtio_vsock_probe+0xef/0x6b0 Freed by task 84: kfree+0x131/0x3c0 virtio_vsock_remove+0xd1/0x100 Flush the works in producer-to-consumer order. virtio_vsock_vqs_del() has already disabled the queue callbacks and cleared the run flags, so after tx_work and send_pkt_work are drained, no source remains that can queue rx_work after its flush.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <728836ebca239810f164262b10211ef59182f811; patch: 6.1.188; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <2187a56f2fd1715d54daed6392809223c60544f3; 4.8; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <f3313d952fc380cff53db9a28451a8807aa67b43; patch: 6.6.157; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <531e2ac2dab1ab90a16427c4f9c86663633e9487; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <da5e9f08714c19ba04e6863aca69d40f042f2e04; patch: 6.12.109; patch: 5.15.221; patch: 0; patch: 6.18.50; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <e059a14c1067bcc4f7b1947cd09f2baab98e340f; patch: 7.2.4; patch: 7.3-rc1; 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 <165a330a68b5f299d8735f0194c314cb2e571269; patch: 5.10.270
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.