Local privilege escalation via managed-page reference underflow
Published Jul 13, 2026 · Updated Jul 13, 2026
Page-reference underflow in Linux Kernel virtio-vsock zerocopy sends allows local users to gain root privileges through AF_VSOCK. In the multi-SKB path, managed io_uring SEND_ZC pages lack fragment references, yet __skb_frag_unref() calls put_page(), draining the pin until a still-pinned page is freed. A low-privileged local process with AF_VSOCK and io_uring access can reclaim the page as setuid executable page cache and rewrite its interpreter path for root execution.
Summary
What happened
Page-reference underflow in Linux Kernel virtio-vsock zerocopy sends allows local users to gain root privileges through AF_VSOCK. In the multi-SKB path, managed io_uring SEND_ZC pages lack fragment references, yet __skb_frag_unref() calls put_page(), draining the pin until a still-pinned page is freed. A low-privileged local process with AF_VSOCK and io_uring access can reclaim the page as setuid executable page cache and rewrite its interpreter path for root execution.
The record
- CVE
- CVE-2026-53365
- Published
- Jul 13, 2026
- Updated
- Jul 13, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux Kernel
- Classifications
- CWE-404, CWE-401, T1068
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jul 13, 2026CVE publishedPublication date reported by the CVE source.
- Jul 13, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=581512a6dc939ef122e49336626ae159f3b8a345 <76b995bc57bd90cb6e954e1966fbd8786da47f0d
- Affected versionversion=581512a6dc939ef122e49336626ae159f3b8a345 <ae38d9179190a956e2a87a69ef1dd6f451b51c4d
- Affected versionversion=581512a6dc939ef122e49336626ae159f3b8a345 <b3155f2b78db21e99256bcf7eb902f24ff6d5338
- Affected versionversion=6.7
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- VsockDropfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo