{"id":"CVE-2026-74614","summary":"vsock/virtio: read virtqueues under worker locks","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: read virtqueues under worker locks\n\nCommit bd50c5dc182b (\"vsock/virtio: add support for device\nsuspend/resume\") made the *_run flags transition from false to true when\nrestore installs replacement virtqueues.  The RX, TX and event workers\nread their virtqueue before locking and checking the corresponding flag,\nso a worker delayed across freeze and restore can observe the replacement\nqueue's running state while retaining a pointer to the deleted queue.\n\nRead each virtqueue under its mutex after checking the run flag, keeping\nthe pointer and state in the same queue generation.","modified":"2026-08-27T11:30:27.464675192Z","published":"2026-08-22T15:31:59.800Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74614.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1cecb4202afdbeddcf29d59baf596ac6ab753f7f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/29dd10583bf9d2744cd84b862e4257c0a5699570"},{"type":"WEB","url":"https://git.kernel.org/stable/c/941329ce14c5f481223a10d1d4c8b57ea7f3048a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a1fb0c5b8a7c2753758aeced40971f99449dde0c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bd43a7ec668be428265b3209eb43647aedcf720a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eae099c764c7ebdb842eb1f638913e310bdd6513"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ebac8f6b1ef0e9278afe204b8692a7479988dace"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74614.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74614"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"762c251c7f5c4ee5bef71460c6e822ed293fd69f"},{"fixed":"941329ce14c5f481223a10d1d4c8b57ea7f3048a"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"bd50c5dc182b0a52599f87b429f9a5a9cbfc9b1c"},{"fixed":"29dd10583bf9d2744cd84b862e4257c0a5699570"},{"fixed":"a1fb0c5b8a7c2753758aeced40971f99449dde0c"},{"fixed":"eae099c764c7ebdb842eb1f638913e310bdd6513"},{"fixed":"bd43a7ec668be428265b3209eb43647aedcf720a"},{"fixed":"1cecb4202afdbeddcf29d59baf596ac6ab753f7f"},{"fixed":"ebac8f6b1ef0e9278afe204b8692a7479988dace"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5.15.138"},{"fixed":"5.15.216"}]}],"versions":["v5.15.215","v5.15.214","v5.15.213","v5.15.212","v5.15.211","v5.15.210","v5.15.209","v5.15.208","v5.15.207","v5.15.206","v5.15.205","v5.15.204","v5.15.203","v5.15.202","v5.15.201","v5.15.200","v5.15.199","v5.15.198","v5.15.197","v5.15.196","v5.15.195","v5.15.194","v5.15.193","v5.15.192","v5.15.191","v5.15.190","v5.15.189","v5.15.188","v5.15.187","v5.15.186","v5.15.185","v5.15.184","v5.15.183","v5.15.182","v5.15.181","v5.15.180","v5.15.179","v5.15.178","v5.15.177","v5.15.176","v5.15.175","v5.15.174","v5.15.173","v5.15.172","v5.15.171","v5.15.170","v5.15.169","v5.15.168","v5.15.167","v5.15.166","v5.15.165","v5.15.164","v5.15.163","v5.15.162","v5.15.161","v5.15.160","v5.15.159","v5.15.158","v5.15.157","v5.15.156","v5.15.155","v5.15.154","v5.15.153","v5.15.152","v5.15.151","v5.15.150","v5.15.149","v5.15.148","v5.15.147","v5.15.146","v5.15.145","v5.15.144","v5.15.143","v5.15.142","v5.15.141","v5.15.140","v5.15.139","v5.15.138"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74614.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.216"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.183"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.19.0"},{"fixed":"6.6.152"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.12.104"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.18.45"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"7.1.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74614.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}