Database/Kernel, userspace & hypervisor
virtio-win Viosock: integer overflow in the select IOCTL overflows a NonPagedPool array and escalates in the guest
Impact
A low-privileged process in a Windows guest can submit IOCTL_SELECT with fd_count values whose 32-bit sum wraps, slipping past the FD_SETSIZE check; VIOSockSelectCopyFds then writes past the allocated Fds array in the NonPagedPool kernel heap. The result is kernel memory corruption and privilege escalation inside that guest. The blast radius stops at the guest: nothing in the record indicates a path out to the KVM host or to other VMs, so for an operator this is a guest-hardening issue, not a tenant-isolation break. It matters where Windows VMs sit on the fleet - vGPU-backed VDI, Windows render or CAD nodes - and where the guest administrator boundary is something you actually rely on.
Who can reach it
Local, inside a Windows guest running the virtio-win Viosock driver (versions mm210 through mm319). Any authenticated low-privilege local process that can open the vsock device and issue the IOCTL; no host or hypervisor access is needed.
What to do
Update the virtio-win guest drivers to mm320 in each affected Windows VM. Replacing a kernel-mode driver means a guest reboot per VM, not a host reboot - the hypervisor and the GPU host stack are untouched, so this rolls out as a guest patch cycle rather than a fleet maintenance window. Guests that do not use vsock can have the Viosock driver left uninstalled as a mitigation.
References
Related entries
- FreeBSD ZFS: size truncation in ZFS_IOC_USERSPACE_MANY gives a local user a kernel heap overflowCVE-2026-49429 · FreeBSD ZFS (ZFS_IOC_USERSPACE_MANY ioctl)High
- Linux kernel SO_REUSEPORT: cBPF program freed without an RCU grace period, use-after-free in UDP receiveCVE-2026-52910 · Linux kernel net/core sock_reuseport (cBPF program freed without RCU grace period)High
- Linux kernel io_uring poll: cancel flag makes the ownership slowpath unreachableCVE-2026-52933 · Linux kernel io_uring (io_poll_get_ownership signed refcount comparison)High
- Linux kernel (net/xfrm): ESP-in-TCP keeps a single in-flight transmit. For a blocking caller the flush of that stateCVE-2026-52935 · Linux kernel (net/xfrm)High
- Linux kernel PSI: use-after-free racing a cgroup pressure write against cgroup removalCVE-2026-52991 · Linux kernel sched/psi (cgroup pressure files)High
- Linux kernel ice driver: double free of transmit skb on the TSO/checksum error pathCVE-2026-53009 · Linux kernel ice driver (Intel E810 transmit path tx_buf handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.