# CVE-2026-80932

## Summary

- **CVE ID:** CVE-2026-80932
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: flush works in dependency order

virtio_vsock_remove() stops the virtqueues and then flushes each work
item before freeing the enclosing virtio_vsock.  The current order does
not account for dependencies between those items: tx_work may queue
send_pkt_work, and send_pkt_work may queue rx_work.

In particular, send_pkt_work can set restart_rx and release tx_lock.
The remove path can then stop the queues and flush rx_work before
send_pkt_work queues it.  Although the later send_pkt_work flush waits
for that producer to finish, nothing waits for the newly queued rx_work,
so kfree(vsock) can race with it.

KASAN reported:

  BUG: KASAN: slab-use-after-free in
  virtio_transport_rx_work+0x487/0x4b0
  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47
  Workqueue: virtio_vsock virtio_transport_rx_work
  Call Trace:
   virtio_transport_rx_work+0x487/0x4b0
   process_one_work+0x688/0x1120
   worker_thread+0x45b/0xd10
  Allocated by task 1:
   virtio_vsock_probe+0xef/0x6b0
  Freed by task 84:
   kfree+0x131/0x3c0
   virtio_vsock_remove+0xd1/0x100

Flush the works in producer-to-consumer order.  virtio_vsock_vqs_del()
has already disabled the queue callbacks and cleared the run flags, so
after tx_work and send_pkt_work are drained, no source remains that can
queue rx_work after its flush.

## Affected Products

- Linux — Linux (0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872)
- Linux — Linux (4.8)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3)
- [CNA](https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269)
- [CNA](https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04)
- [CNA](https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811)
- [CNA](https://git.kernel.org/stable/c/e059a14c1067bcc4f7b1947cd09f2baab98e340f)
- [CNA](https://git.kernel.org/stable/c/531e2ac2dab1ab90a16427c4f9c86663633e9487)
- [CNA](https://git.kernel.org/stable/c/f3313d952fc380cff53db9a28451a8807aa67b43)
- [CNA](https://git.kernel.org/stable/c/b9cb4e8ba71c9fbd935d66baa71bbb0b87192c94)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._