PT-2026-44357 · Linux · Linux
Published
2026-05-28
·
Updated
2026-05-28
·
CVE-2026-46234
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
vsock: fix buffer size clamping order
In vsock update buffer size(), the buffer size was being clamped to the
maximum first, and then to the minimum. If a user sets a minimum buffer
size larger than the maximum, the minimum check overrides the maximum
check, inverting the constraint.
This breaks the intended socket memory boundaries by allowing the
vsk->buffer size to grow beyond the configured vsk->buffer max size.
Fix this by checking the minimum first, and then the maximum. This
ensures the buffer size never exceeds the buffer max size.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux