vsock/virtio: fix zerocopy completion for multi-skb sends
Published Jul 13, 2026
7.8
HIGHCVSS 3.1
EPSS 0.20%
Description
When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe to reuse. If the loop breaks early the uarg is never allocated at all, leaking pinned pages with no completion notification.
Fix this by following the approach used by TCP: allocate the zerocopy uarg (if not provided by the caller) before the send loop and attach it to every skb via skb_zcopy_set(), which takes a reference per skb. Each skb's completion properly decrements the refcount, and the notification only fires after the last skb is freed. On failure, if no data was sent, the uarg is cleanly aborted via net_zcopy_put_abort().
This issue was initially discovered by sashiko while reviewing commit 1cb36e252211 ("vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting") but was pre-existing.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.7StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.7
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.34StatusunaffectedConstraints<=6.18.*
- Version 7.0.11StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.7 · < 6.18.34
- ≥ 6.19 · < 7.0.11
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 9.2 and earlier are not affected by this flaw. The vulnerable code was introduced by the upstream commit that added MSG_ZEROCOPY support to the virtio-vsock transport (581512a). This feature was not backported to RHEL 9.2 or earlier kernel versions, so the affected zerocopy transmit code path does not exist in those kernels.
Red Hat mitigation
The vulnerable code path is only reachable when using virtio-vsock with zerocopy transmit on virtual machines using the vhost-vsock or virtio-vsock transport. Systems that do not use VM socket communication (AF_VSOCK) are not affected. To prevent the vulnerable code path from being reached, the vhost_vsock kernel module can be unloaded and blacklisted if vsock functionality is not required: ``` modprobe -r vhost_vsock echo "blacklist vhost_vsock" > /etc/modprobe.d/vsock-blacklist.conf ``` Systems that rely on VM-to-host socket communication (e.g., QEMU guest agent communication) cannot use this mitigation and should prioritize applying the kernel fix.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 18, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jul-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.20% (0.00197) | 8.49th | v5 (v2026.06.15) |
| Jul 14, 2026 | 0.15% (0.00155) | 5.08th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-53365 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2499742 Issue Tracking
- https://git.kernel.org/stable/c/293fe8f2d1b5ac464ca16a8eba09571bbbb34ba9
- https://git.kernel.org/stable/c/76b995bc57bd90cb6e954e1966fbd8786da47f0d Patch
- https://git.kernel.org/stable/c/ae38d9179190a956e2a87a69ef1dd6f451b51c4d Patch
- https://git.kernel.org/stable/c/b3155f2b78db21e99256bcf7eb902f24ff6d5338 Patch
- https://github.com/MaherAzzouzi/vsockdrop exploit
- https://lore.kernel.org/linux-cve-announce/2026071353-CVE-2026-53365-c6d2@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53365
- https://www.cve.org/CVERecord?id=CVE-2026-53365
Change history (0)
No recorded changes yet.