CVE-2026-64115

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> vsock/vmci: fix UAF when peer resets connection during handshake<br /> <br /> vmci_transport_recv_connecting_server() returned err = 0 for a peer<br /> RST in its default switch arm:<br /> <br /> err = pkt-&gt;type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL;<br /> <br /> That made vmci_transport_recv_listen() skip vsock_remove_pending(),<br /> leaving the pending socket on the listener&amp;#39;s pending_links with<br /> sk_state = TCP_CLOSE while destroy: still dropped the explicit<br /> reference taken before schedule_delayed_work().<br /> <br /> One second later vsock_pending_work() observed is_pending=true and<br /> performed full cleanup: vsock_remove_pending() then the two trailing<br /> sock_put(sk) calls -- the first reached refcount 0 and __sk_freed<br /> the socket, and the second wrote into the freed object:<br /> <br /> BUG: KASAN: slab-use-after-free in refcount_warn_saturate<br /> Write of size 4 at addr ffff88800b1cac80 by task kworker<br /> Workqueue: events vsock_pending_work<br /> <br /> Treat peer RST like any other unexpected packet type (err = -EINVAL).<br /> All destroy: arms now return err