Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-53365

 

Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-53365

Published: July 14, 2026 / Updated: August 21, 2026


Vulnerability identifier: #VU137403
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53365
CWE-ID: CWE-772
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in virtio vsock zerocopy completion handling in net/vmw_vsock/virtio_transport_common.c when processing multi-skb MSG_ZEROCOPY sends. A local user can send a large crafted message that is fragmented into multiple skbs to cause a denial of service.

The issue can leave pinned user pages without completion notification, including when the send loop exits before the final skb is processed.


Affected software

Linux kernel
Debian Linux
Ubuntu
linux (Debian package)
linux (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-bos (Ubuntu package)

How to mitigate CVE-2026-53365

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.100-1
linux (Ubuntu package) - addressed in versions 7.0.0-28.28, 7.0.0-28.28.1, 7.0.0-1003.4, 7.0.0-1008.8
linux-ibm (Ubuntu package) - addressed in versions 7.0.0-1008.8, 7.0.0-1010.10
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1009.9
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1010.10
linux-aws (Ubuntu package) - addressed in versions 7.0.0-1009.9, 7.0.0-1015.15
linux-nvidia (Ubuntu package) - addressed in versions 7.0.0-1016.16, 7.0.0-1016.16~24.04.1
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2016.16

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins