Linux Kernel Vulnerability in Vsock and Virtio Transport
CVE-2026-63970

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63970?

This vulnerability in the Linux kernel affects the vsock and virtio transport layers by improperly allocating or reusing zerocopy user arguments before entering the send loop. When certain conditions are met, it may cause issues with fragmented SKB (socket buffers), subsequently leading to memory management problems. Specifically, the mishandling can result in a failure to properly reference managed fragments, which poses risks during data transmission. The issue has been addressed by ensuring that user arguments are passed correctly into the allocation function and binding them before filling the SKB, maintaining control and integrity throughout the process.

Affected Version(s)

Linux 581512a6dc939ef122e49336626ae159f3b8a345

Linux 581512a6dc939ef122e49336626ae159f3b8a345 < 5d317573f1d48e76cce5fb6250452b6e4102e0fb

Linux 581512a6dc939ef122e49336626ae159f3b8a345 < 1e584c304cfb94a759417130b1fc6d30b30c4cce

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.