Allocation of Resources Without Limits or Throttling in Linux kernel - CVE-2026-53132

 

Allocation of Resources Without Limits or Throttling in Linux kernel - CVE-2026-53132

Published: June 26, 2026


Vulnerability identifier: #VU135652
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53132
CWE-ID: CWE-770
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in virtio_transport_inc_rx_pkt() and the virtio vsock receive queue when processing crafted packets with zero-length payloads and the VIRTIO_VSOCK_SEQ_EOM flag. A local user can send a large number of specially crafted packets to cause a denial of service.

The issue occurs because queued packets may not increase the tracked byte count, allowing the receive queue to grow excessively.


Affected software

Linux kernel
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo

How to mitigate CVE-2026-53132

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel - update to 6.6.0-145.1.20.157
bpftool - update to 6.6.0-145.1.20.157
bpftool-debuginfo - update to 6.6.0-145.1.20.157
kernel-debuginfo - update to 6.6.0-145.1.20.157
kernel-debugsource - update to 6.6.0-145.1.20.157
kernel-devel - update to 6.6.0-145.1.20.157
kernel-headers - update to 6.6.0-145.1.20.157
kernel-source - update to 6.6.0-145.1.20.157
kernel-tools - update to 6.6.0-145.1.20.157
kernel-tools-debuginfo - update to 6.6.0-145.1.20.157
kernel-tools-devel - update to 6.6.0-145.1.20.157
perf - update to 6.6.0-145.1.20.157
perf-debuginfo - update to 6.6.0-145.1.20.157
python3-perf - update to 6.6.0-145.1.20.157
python3-perf-debuginfo - update to 6.6.0-145.1.20.157

External References

Related Security Bulletins