MEDIUM

CVE-2026-52994

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting

virtio_transport_init_zcopy_skb() uses iter->count as the size argument
for msg_zerocopy_realloc(), which in turn passes it to
mm_account_pinned_pages() for RLIMIT_MEMLOCK accounting. However, this
function is called after virtio_transport_fill_skb() has already consumed
the iterator via __zerocopy_sg_from_iter(), so on the last skb, iter->count
will be 0, skipping the RLIMIT_MEMLOCK enforcement.

Pass pkt_len (the total bytes being sent) as an explicit parameter to
virtio_transport_init_zcopy_skb() instead of reading the already-consumed
iter->count.

This matches TCP and UDP, which both call msg_zerocopy_realloc() with
the original message size.

Summary dbcve.org

The vsock/virtio transport in the Linux kernel fails to properly enforce RLIMIT_MEMLOCK during MSG_ZEROCOPY operations. After virtio_transport_fill_skb() consumes the iterator via __zerocopy_sg_from_iter(), subsequent calls to virtio_transport_init_zcopy_skb() read iter->count which becomes 0 on the last skb, causing memory pinning accounting to be skipped entirely. This allows local users to bypass memory locking limits.

Mitigation

Apply the upstream kernel patch to pass pkt_len (total bytes being sent) as an explicit parameter to virtio_transport_init_zcopy_skb() instead of relying on the consumed iter->count, matching TCP/UDP behavior.

Patch Commit

EPSS Score

0.13%
Probability of exploitation in next 30 days
2.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE