Updated: 2026-01-08 03:08:07.20741
Description:
In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but is not on the list of unbound sockets. Binding it will result in an extra refcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep the binding until socket destruction). Modify the check in __vsock_bind_connectible() to also prevent binding to VMADDR_PORT_ANY.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | HIGH | 7.8 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | kernel | 5.14.0 | 7.8 | HIGH | Released | CLSA-2026:1768663754 | 2026-01-17 19:36:15 | |
| CentOS 7 ELS | kernel | 3.10.0 | 7.8 | HIGH | In Testing | 2026-02-09 21:42:36 | ||
| CentOS 8.4 ELS | kernel | 4.18.0 | 7.8 | HIGH | Released | CLSA-2026:1768774361 | 2026-01-19 09:32:44 | |
| CentOS 8.5 ELS | kernel | 4.18.0 | 7.8 | HIGH | Released | CLSA-2026:1768775579 | 2026-01-19 09:32:46 | |
| CentOS Stream 8 ELS | kernel | 4.18.0 | 7.8 | HIGH | Released | CLSA-2026:1770032032 | 2026-02-02 15:05:42 | |
| CloudLinux 7 ELS | kernel | 3.10.0 | 7.8 | HIGH | Needs Triage | 2026-01-08 07:16:09 | ||
| Oracle Linux 7 ELS | kernel | 3.10.0 | 7.8 | HIGH | Needs Triage | 2026-01-08 16:47:35 | ||
| Oracle Linux 7 ELS | kernel-uek | 5.4.17 | 7.8 | HIGH | Already Fixed | 2026-02-04 01:20:50 | ||
| RHEL 7 ELS | kernel | 3.10.0 | 7.8 | HIGH | Needs Triage | 2026-01-08 07:16:10 | ||
| TuxCare 9.6 ESU | kernel | 5.14.0 | 7.8 | HIGH | In Testing | 2026-02-05 12:40:57 |