Back

HIGH

vsock/virtio: fix zerocopy completion for multi-skb sends

Published Jul 13, 2026

Description

When a large message is fragmented into multiple skbs, the zerocopy uarg is only allocated and attached to the last skb in the loop. Non-final skbs carry pinned user pages with no completion tracking, so the kernel has no way to notify userspace when those pages are safe to reuse. If the loop breaks early the uarg is never allocated at all, leaking pinned pages with no completion notification.

Fix this by following the approach used by TCP: allocate the zerocopy uarg (if not provided by the caller) before the send loop and attach it to every skb via skb_zcopy_set(), which takes a reference per skb. Each skb's completion properly decrements the refcount, and the notification only fires after the last skb is freed. On failure, if no data was sent, the uarg is cleanly aborted via net_zcopy_put_abort().

This issue was initially discovered by sashiko while reviewing commit 1cb36e252211 ("vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting") but was pre-existing.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 9.2 and earlier are not affected by this flaw. The vulnerable code was introduced by the upstream commit that added MSG_ZEROCOPY support to the virtio-vsock transport (581512a). This feature was not backported to RHEL 9.2 or earlier kernel versions, so the affected zerocopy transmit code path does not exist in those kernels.

Red Hat mitigation

The vulnerable code path is only reachable when using virtio-vsock with zerocopy transmit on virtual machines using the vhost-vsock or virtio-vsock transport. Systems that do not use VM socket communication (AF_VSOCK) are not affected. To prevent the vulnerable code path from being reached, the vhost_vsock kernel module can be unloaded and blacklisted if vsock functionality is not required: ``` modprobe -r vhost_vsock echo "blacklist vhost_vsock" > /etc/modprobe.d/vsock-blacklist.conf ``` Systems that rely on VM-to-host socket communication (e.g., QEMU guest agent communication) cannot use this mitigation and should prioritize applying the kernel fix.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 13, 2026
Updated Aug 18, 2026
Reserved Jun 9, 2026
CISA Vulnrichment
Updated Aug 18, 2026
NVD
Status Modified
Modified Aug 18, 2026
Red Hat
Severity Important
Public date Jul 13, 2026