CVE-2026-46207 Details
Description
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix empty payload in tap skb for non-linear buffers For non-linear skbs, virtio_transport_build_skb() goes through virtio_transport_copy_nonlinear_skb() to copy the original payload in the new skb to be delivered to the vsockmon tap device. This manually initializes an iov_iter but does not set iov_iter.count. Since the iov_iter is zero-initialized, the copy length is zero and no payload is actually copied to the monitor interface, leaving data un-initialized. Fix this by removing the linear vs non-linear split and using skb_copy_datagram_iter() with iov_iter_kvec() for all cases, as vhost-vsock already does. This handles both linear and non-linear skbs, properly initializes the iov_iter, and removes the now unused virtio_transport_copy_nonlinear_skb(). While touching this code, let's also check the return value of skb_copy_datagram_iter(), even though it's unlikely to fail.
A vulnerability exists in the Linux kernel's virtio transport for vsock, specifically in how it handles non-linear socket buffers (skbs). When non-linear skbs are processed, the function responsible for building the skb for the vsock monitor tap device fails to correctly initialize the iteration state needed to copy the payload. This oversight leaves the copied data uninitialized, potentially leading to undefined behavior. The issue arises because the iteration state is initialized to zero, resulting in no data being transferred to the monitor interface. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed by modifying the skb handling to correctly manage both linear and non-linear cases. Users should upgrade to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/06747f52ab157591cec7e5623a759473b66ef6f6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/378b131a25bd1a5ee27ca199fe486c299d5350c5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3a3e3d90cbc79600544536723911657730759af3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/52da6a74ca3de0fcda60301096b71534b3b18641 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.7, < 6.12.90 >= 6.13, < 6.18.32 >= 6.19, < 7.0.9 7.1 rc1 7.1 rc2 7.1 rc3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 10, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | kernel.org |