---
id: CVE-2026-52994
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting

  virtio_transport_init_zcopy_skb() uses iter->count as the size argument
  for msg_zerocopy_realloc(), which in tur…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting

  virtio_transport_init_zcopy_skb() uses iter->count as the size argument
  for msg_zerocopy_realloc(), which in tur…
severity: none
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52994'
references:
  - url: 'https://git.kernel.org/stable/c/1cb36e252211506f51095fe7ced8286cc77b4c80'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6af1736b5810bc8a4a43a8518530113f5a757dc1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d0117950075f0a9d5944980784c719d8ebcd4bff'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.0016
epssPercentile: 0.04453
ingestedAt: '2026-07-11T13:13:25.661Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting

virtio_transport_init_zcopy_skb() uses iter->count as the size argument
for msg_zerocopy_realloc(), which in turn passes it to
mm_account_pinned_pages() for RLIMIT_MEMLOCK accounting. However, this
function is called after virtio_transport_fill_skb() has already consumed
the iterator via __zerocopy_sg_from_iter(), so on the last skb, iter->count
will be 0, skipping the RLIMIT_MEMLOCK enforcement.

Pass pkt_len (the total bytes being sent) as an explicit parameter to
virtio_transport_init_zcopy_skb() instead of reading the already-consumed
iter->count.

This matches TCP and UDP, which both call msg_zerocopy_realloc() with
the original message size.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
