Home

Description

In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping order In vsock_update_buffer_size(), the buffer size was being clamped to the maximum first, and then to the minimum. If a user sets a minimum buffer size larger than the maximum, the minimum check overrides the maximum check, inverting the constraint. This breaks the intended socket memory boundaries by allowing the vsk->buffer_size to grow beyond the configured vsk->buffer_max_size. Fix this by checking the minimum first, and then the maximum. This ensures the buffer size never exceeds the buffer_max_size.

PUBLISHED Reserved 2026-05-13 | Published 2026-05-28 | Updated 2026-06-01 | Assigner Linux

Product status

Default status
unaffected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before f6ec135941d2c1c2dbb87b5ce1783f4f6ac6ccca
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before caf11dfea5233a69298a1c448bbf8d1639c80536
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before 01ef69785dc3162f588a361ab770b1e312800188
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before a998a7e250bf976539e05a00ec64a81292afecaa
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before 310da27932dd0afe7ce7456dfe1f0814c3301f41
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before 2602f7bb5818e92315feeaeb71d8ce4d5c9ab160
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before 0b68881501460c3761f196469e1e503218c5e536
affected

b9f2b0ffde0c9b666b2b1672eb468b8f805a9b97 (git) before d114bfdc9b76bf93b881e195b7ec957c14227bab
affected

Default status
affected

5.5
affected

Any version before 5.5
unaffected

5.10.258 (semver)
unaffected

5.15.209 (semver)
unaffected

6.1.175 (semver)
unaffected

6.6.140 (semver)
unaffected

6.12.90 (semver)
unaffected

6.18.32 (semver)
unaffected

7.0.9 (semver)
unaffected

7.1-rc1 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/f6ec135941d2c1c2dbb87b5ce1783f4f6ac6ccca

git.kernel.org/...c/caf11dfea5233a69298a1c448bbf8d1639c80536

git.kernel.org/...c/01ef69785dc3162f588a361ab770b1e312800188

git.kernel.org/...c/a998a7e250bf976539e05a00ec64a81292afecaa

git.kernel.org/...c/310da27932dd0afe7ce7456dfe1f0814c3301f41

git.kernel.org/...c/2602f7bb5818e92315feeaeb71d8ce4d5c9ab160

git.kernel.org/...c/0b68881501460c3761f196469e1e503218c5e536

git.kernel.org/...c/d114bfdc9b76bf93b881e195b7ec957c14227bab

cve.org (CVE-2026-46234)

nvd.nist.gov (CVE-2026-46234)

Download JSON