Database/Kernel, userspace & hypervisor
Linux kernel (vsock/virtio): Dangling pointer in vsk
CVSS 6.0CVE-2024-50264Kernel, userspace & hypervisorcurated
Impact
Dangling pointer in vsk->trans during AF_VSOCK connect - use-after-free, local root; vsock is the host/guest channel on virtualised nodes
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Livepatchable; otherwise drain + reboot. Blacklist vsock modules on nodes that do not use them
References
Related entries
- Linux kernel (drivers/gpu/drm/scheduler): When one tenant's scheduler entity is killed, its scheduled fences are notCVE-2025-38436 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Linux kernel (drivers/gpu/drm/xe): A batched array of VM_BIND operations could evict other buffer objects belonging toCVE-2025-40086 · Linux kernel (drivers/gpu/drm/xe)Medium
- Linux kernel (drivers/gpu/drm/scheduler): Tearing down a GPU scheduler entity takes locks from a fence-signallingCVE-2025-40329 · Linux kernel (drivers/gpu/drm/scheduler)Medium
- Intel CPU (MDS / ZombieLoad): Microarchitectural Fill Buffer Data SamplingCVE-2018-12130 · Intel CPU (MDS / ZombieLoad)Medium
- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessCVE-2022-49434 · Linux kernel (drivers/pci)Medium
- OpenSSH (transport): Terrapin: prefix-truncation attack on the SSH Binary Packet ProtocolCVE-2023-48795 · OpenSSH (transport)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.