CVE-2026-53132: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc. virtio_transport_recv_enqueue() skips coalescing for packets with VIRTIO_VSOCK_SEQ_EOM. If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs->rx_bytes stays at 0. Fix this by estimating the skb metadata size: (Number of skbs in the queue) * SKB_TRUESIZE(0)
Affected products
- Linux Linux Kernel: from 6.1.63, before 6.2 (fixed in 6.2); from 6.3.1, before 6.12.94 (fixed in 6.12.94); from 6.13, before 6.18.36 (fixed in 6.18.36); from 6.19, before 7.0.13 (fixed in 7.0.13); version 6.3 only; version 7.1 only
Published 2026-06-25. Last modified 2026-07-06.