CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: bind uarg before filling zerocopy skb
virtiotransportsendpktinfo() allocates or reuses the zerocopy uarg before entering the send loop, but virtiotransportallocskb() still fills the skb before it inherits that uarg. When fixed-buffer vectored zerocopy hits MAXSKBFRAGS, iosgfromiter() may partially attach managed frags and return -EMSGSIZE. The rollback path call kfreeskb() to free an skb that carries SKBFLMANAGEDFRAGREFS but no uarg, so skbreleasedata() falls through to ordinary frag unref.
Pass the uarg into virtiotransportallocskb() and bind it immediately before virtiotransportfillskb(). This keeps control or no-payload skbs untouched while ensuring success and rollback share one lifetime rule.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63970?
CVE-2026-63970 has a risk rating of 38, indicating a significant vulnerability in the Linux kernel.
How do I fix CVE-2026-63970?
To fix CVE-2026-63970, ensure you update your Linux kernel to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-63970?
CVE-2026-63970 affects various distributions of the Linux kernel that use the vsock and virtio components.
What types of exploits are possible with CVE-2026-63970?
Potential exploits of CVE-2026-63970 could allow unauthorized access or manipulation of network packets.
When was CVE-2026-63970 published?
CVE-2026-63970 was published on July 19, 2026.