Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46655

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 7.8

Описание

A flaw was found in virtio-win. A low-integrity process can issue an IOCTL request to viosock.sys!VIOSockSelect with a maliciously crafted request that causes an integer overflow. This allows the process to circumvent bounds checking, resulting in a heap overflow in the NonPagedPool kernel heap. The flaw could be exploited to escalate privileges on Windows systems running this driver.

Меры по смягчению последствий

This flaw requires local access to a Windows guest with the virtio-vsock driver installed. The following steps reduce exposure:

  1. Disable the viosock driver on guests that do not need VM socket communication. Stop the viosock service and set its startup type to Disabled. This eliminates the attack surface entirely and is the strongest interim mitigation.
  2. Verify memory protections are active in the guest. These raise the cost of exploiting the heap overflow significantly.
  3. Minimize guest-to-host attack surface on the hypervisor. Even a full guest kernel compromise is contained by the KVM boundary. Disable unnecessary virtio devices and limit PCI passthrough to reduce the risk of chaining with a separate host escape.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10virtio-winAffected
Red Hat Enterprise Linux 8virtio-winWill not fix
Red Hat Enterprise Linux 9virtio-winAffected
Red Hat OpenShift Virtualization 4container-native-virtualization/virtio-winNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2489170virtio-win: viosock.sys: integer overflow in VIOSockSelect leads to heap-based buffer overflow

7.8 High

CVSS3

7.8 High

CVSS3