In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: cap TX credit to local buffer size
The virtio transports derives its TX credit directly from peer_buf_alloc, which is set from the remote endpoint's SO_VM_SOCKETS_BUFFER_SIZE value.
On the host side this means that the amount of data we are willing to queue for a connection is scaled by a guest-chosen buffer size, rather than the host's own vsock configuration. A malicious guest can advertise a large buffer and read slowly, causing the host to allocate a correspondingly large amount of sk_buff memory. The same thing would happen in the guest with a malicious host, since virtio transports share the same code base.
Introduce a small helper, virtio_transport_tx_buf_size(), that returns min(peer_buf_alloc, buf_alloc), and use it wherever we consume peer_buf_alloc.
This ensures the effective TX window is bounded by both the peer's advertised buffer and our own buf_alloc (already clamped to buffer_max_size via SO_VM_SOCKETS_BUFFER_MAX_SIZE), so a remote peer cannot force the other to queue more data than allowed by its own vsock settings.
On an unpatched Ubuntu 22.04 host (~64 GiB RAM), running a PoC with 32 guest vsock connections advertising 2 GiB each and reading slowly drove Slab/SUnreclaim from ~0.5 GiB to ~57 GiB; the system only recovered after killing the QEMU process. That said, if QEMU memory is limited with cgroups, the maximum memory used will be limited.
With this patch applied:
Before: MemFree: ~61.6 GiB Slab: ~142 MiB SUnreclaim: ~117 MiB
After 32 high-credit connections: MemFree: ~61.5 GiB Slab: ~178 MiB SUnreclaim: ~152 MiB
Only ~35 MiB increase in Slab/SUnreclaim, no host OOM, and the guest remains responsive.
Compatibility with non-virtio transports:
- VMCI uses the AF_VSOCK buffer knobs to size its queue pairs per socket based on the local vsk->buffer_* values; the remote side cannot enlarge those queues beyond what the local endpoint configured.
- Hyper-V's vsock transport uses fixed-size VMBus ring buffers and an MTU bound; there is no peer-controlled credit field comparable to peer_buf_alloc, and the remote endpoint cannot drive in-flight kernel memory above those ring sizes.
- The loopback path reuses virtio_transport_common.c, so it naturally follows the same semantics as the virtio transport.
This change is limited to virtio_transport_common.c and thus affects virtio-vsock, vhost-vsock, and loopback, bringing them in line with the "remote window intersected with local policy" behaviour that VMCI and Hyper-V already effectively have.
[Stefano: small adjustments after changing the previous patch] [Stefano: tweak the commit message]
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.12-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-tools-debuginfoUpgrade kernel6.12-libbpf-debuginfoUpgrade kernel6.12-headersUpgrade kernel-debuginfoUpgrade kernel6.12-debuginfo-common-x86_64Upgrade perf6.12Upgrade kernel6.12Upgrade kernel-libbpfUpgrade kernel-headersUpgrade kernel6.12-modules-extraUpgrade perfUpgrade python3-perf-debuginfoUpgrade kernel-modules-extraUpgrade bpftool-debuginfoUpgrade kernel6.12-modules-extra-commonUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade kernel-libbpf-debuginfoUpgrade python3-perf6.12Upgrade kernel6.12-develUpgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel-develUpgrade bpftool6.12-debuginfoUpgrade kernel6.12-libbpf-staticUpgrade kernelUpgrade kernel-livepatch-6.12.68-92.122Upgrade kernel-libbpf-develUpgrade kernel6.12-libbpf-develUpgrade python3-perfUpgrade kernel-toolsUpgrade perf6.12-debuginfoUpgrade kernel6.12-libbpfUpgrade kernel6.12-debuginfoUpgrade kernel6.12-tools-debuginfoUpgrade bpftool6.12Upgrade python3-perf6.12-debuginfoUpgrade kernel-libbpf-staticUpgrade kernel-modules-extra-commonUpgrade kernel6.12-toolsUpgrade bpftoolUpgrade kernel-livepatch-6.1.163-186.299Upgrade kernel-tools-devel | Mar 9, 2026 | Feb 4, 2026 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Feb 11, 2026 | Feb 11, 2026 |
| Oracle_linux | — | Upgrade kernel-uek | Mar 25, 2026 | Feb 4, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 4, 2026 |
| Ubuntu | — | Upgrade linux-image-azure-fips-6.8Upgrade linux-image-ibm-6.8Upgrade linux-image-realtime-hwe-24.04Upgrade linux-image-generic-64k-6.8Upgrade linux-image-gke-64k-6.8Upgrade linux-image-oem-6.17Upgrade linux-image-fips-6.8Upgrade linux-image-generic-6.8Upgrade linux-image-aws-lts-24.04Upgrade linux-image-realtime-6.17Upgrade linux-image-xilinxUpgrade linux-image-6.17.0-1021-gcp-64kUpgrade linux-image-6.8.0-1056-raspiUpgrade linux-image-6.17.0-1019-oracleUpgrade linux-image-aws-6.8Upgrade linux-image-6.17.0-1019-oracle-64kUpgrade linux-image-oem-24.04Upgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-realtimeUpgrade linux-image-6.17.0-1031-nvidia-64kUpgrade linux-image-gcp-lts-24.04Upgrade linux-image-6.8.0-1054-nvidiaUpgrade linux-image-6.17.0-1018-azure-fdeUpgrade linux-image-raspi-realtimeUpgrade linux-image-6.8.0-1054-nvidia-lowlatencyUpgrade linux-image-xilinx-6.8Upgrade linux-image-aws-fips-6.8Upgrade linux-image-azure-fipsUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-intel-iotgUpgrade linux-image-azure-lts-24.04Upgrade linux-image-gcpUpgrade linux-image-raspiUpgrade linux-image-virtualUpgrade linux-image-oem-24.04aUpgrade linux-image-nvidia-64k-6.17Upgrade linux-image-oem-24.04dUpgrade linux-image-6.8.0-1059-azure-fipsUpgrade linux-image-gcp-64kUpgrade linux-image-lowlatency-64k-6.8Upgrade linux-image-6.8.0-1024-nvidia-tegraUpgrade linux-image-6.8.0-1054-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1055-awsUpgrade linux-image-raspi-6.8Upgrade linux-image-gcp-fips-6.8Upgrade linux-image-6.8.0-1055-aws-64kUpgrade linux-image-6.8.0-1054-gkeUpgrade linux-image-aws-64k-6.8Upgrade linux-image-nvidia-lowlatency-64k-6.8Upgrade linux-image-azure-6.8Upgrade linux-image-realtime-hwe-22.04Upgrade linux-image-kvmUpgrade linux-image-generic-64kUpgrade linux-image-oracle-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-realtime-6.8.1Upgrade linux-image-intel-iot-realtimeUpgrade linux-image-6.17.0-1021-gcpUpgrade linux-image-gkeUpgrade linux-image-gke-6.8Upgrade linux-image-6.8.0-1024-nvidia-tegra-rtUpgrade linux-image-gcp-6.17Upgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-117-lowlatency-64kUpgrade linux-image-azureUpgrade linux-image-oem-24.04cUpgrade linux-image-6.17.0-1030-oemUpgrade linux-image-6.17.0-1018-realtimeUpgrade linux-image-6.8.0-1058-gcpUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-nvidia-hwe-24.04Upgrade linux-image-6.8.0-1056-azureUpgrade linux-image-virtual-6.8Upgrade linux-image-fipsUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-6.8.0-1041-gkeopUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-gcp-64k-6.8Upgrade linux-image-6.8.0-1055-aws-fipsUpgrade linux-image-nvidia-64k-hwe-24.04Upgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.8.1-1051-realtimeUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-aws-fipsUpgrade linux-image-gkeopUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-azure-fde-6.17Upgrade linux-image-6.8.0-1032-xilinxUpgrade linux-image-azure-6.17Upgrade linux-image-gkeop-6.8Upgrade linux-image-6.8.0-1058-gcp-fipsUpgrade linux-image-lowlatencyUpgrade linux-image-gke-64kUpgrade linux-image-6.8.0-2045-raspi-realtimeUpgrade linux-image-nvidia-lowlatency-6.8Upgrade linux-image-gcp-fipsUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-6.8.0-1054-gke-64kUpgrade linux-image-6.8.0-1054-nvidia-64kUpgrade linux-image-oracleUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-117-genericUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-117-generic-64kUpgrade linux-image-6.8.0-116-fipsUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-117-lowlatencyUpgrade linux-image-nvidia-tegraUpgrade linux-image-nvidia-6.8Upgrade linux-image-lowlatency-6.8Upgrade linux-image-gcp-6.8Upgrade linux-image-azure-fdeUpgrade linux-image-aws-64k-lts-24.04Upgrade linux-image-6.8.0-1059-azureUpgrade linux-image-6.17.0-1021-azureUpgrade linux-image-raspi-realtime-6.8Upgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-6.8.0-1058-gcp-64kUpgrade linux-image-oracle-6.17Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-nvidia-6.17Upgrade linux-image-ibmUpgrade linux-image-genericUpgrade linux-image-6.8.0-1055-ibmUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-oem-24.04bUpgrade linux-image-6.17.0-1031-nvidia | May 25, 2026 | May 19, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub