Allocation of Resources Without Limits or Throttling in Linux kernel - CVE-2026-53132
Published: June 26, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in virtio_transport_inc_rx_pkt() and the virtio vsock receive queue when processing crafted packets with zero-length payloads and the VIRTIO_VSOCK_SEQ_EOM flag. A local user can send a large number of specially crafted packets to cause a denial of service.
The issue occurs because queued packets may not increase the tracked byte count, allowing the receive queue to grow excessively.