CVE-2026-53365 is a Linux kernel vulnerability in the vsock/virtio zerocopy send path affecting large messages fragmented across multiple socket buffers (skbs). During multi-skb sends, the zerocopy user argument used for completion tracking was allocated and attached only to the final skb in the send loop. Earlier skbs could still carry pinned user pages but lacked associated completion tracking, leaving the kernel unable to correctly notify userspace when those pages were safe to reuse. If the send loop terminated early, the zerocopy tracking structure might not be allocated at all, causing pinned pages to remain without completion notification. The fix allocates the zerocopy tracking object before entering the send loop, attaches it to every skb with per-skb reference handling, and aborts it cleanly on failure when no data is sent.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone local privilege escalation exploit for CVE-2026-53365 ('VsockDrop'), targeting a Linux kernel io_uring + AF_VSOCK zero-copy reference-count underflow bug. The repository contains one main exploit source file (exploit.c), two small payload components (interp.c and rootsh.c), a Makefile that compiles the payloads into embedded byte arrays and links a static exploit binary, and bundled liburing headers needed for compilation. Core exploit flow: exploit.c drops two binaries to disk: a minimal freestanding interpreter stub at /tmp/loader and a helper shell launcher at /var/tmp/.s. It then forks a worker process that sets up a local AF_VSOCK listener and sender pinned to CPU 0. The sender allocates and registers a fixed io_uring buffer, uses SO_ZEROCOPY over AF_VSOCK on port 5555, and repeatedly drives the vulnerable multi-SKB SEND_ZC path enough times (default 1024 iterations) to decrement the managed page pin reference count to zero. The exploit then attempts to reclaim the freed page as page cache for /usr/bin/su, locates the ELF page and PT_INTERP string, and overwrites the interpreter path with /tmp/loader. Executing /usr/bin/su causes the kernel to run the attacker-controlled loader with root credentials; that loader changes ownership and mode of /var/tmp/.s to root:root and setuid 04755. After the worker exits and io_uring resources are torn down, the parent verifies the helper became setuid-root and executes it to obtain a real root shell. Payload components: interp.c is a tiny syscall-only ELF interpreter stub whose sole purpose is to chown/chmod the helper and exit. rootsh.c is the final setuid helper that sets uid/gid 0, deletes the dropped artifacts, and execs an interactive shell. This separation avoids spawning the shell while the vulnerable io_uring state is still active. Notable endpoints and artifacts are all local: AF_VSOCK port 5555, /usr/bin/su, /tmp/loader, /var/tmp/.s, and shell paths /bin/bash and /bin/sh. No external network C2 or remote infrastructure is present. Overall, this is a real, weaponizable local exploit with an embedded payload chain, not merely a detector or proof-of-concept crash.
This repository is a standalone local privilege escalation exploit for CVE-2026-53365, not tied to a common exploitation framework. The main code lives under vsockdrop-MaherAzzouzi/ and consists of three authored C sources plus bundled liburing headers and a Makefile. exploit.c is the primary exploit: it creates an AF_VSOCK listener and client on port 5555, enables SO_ZEROCOPY, registers a fixed io_uring buffer, unmaps it, and repeatedly sends >64KB payloads to hit the vulnerable multi-SKB VSOCK zerocopy path. According to the embedded comments and README, each iteration causes one erroneous put_page on a managed fragment, draining the FOLL_LONGTERM pin bias until the still-pinned page is freed and recycled. The exploit then forces a cold read of /usr/bin/su so the freed page is reclaimed as su page cache, locates the ELF page and PT_INTERP string, and overwrites the interpreter path with /tmp/loader using the aliased fixed buffer. It then executes /usr/bin/su so the kernel loads the attacker-controlled interpreter stub with root credentials. The repository includes two embedded payload components compiled and converted into byte arrays during build: interp.c is a minimal freestanding ELF interpreter stub that performs chown/chmod on /var/tmp/.s to make it owned by root and setuid; rootsh.c is the final helper that calls setuid(0)/setgid(0), deletes the staged artifacts, and launches an interactive root shell via /bin/bash or /bin/sh. The Makefile statically builds these stubs, converts them into headers, and links them into a single exploit binary. The included liburing headers support compilation but are not themselves exploit logic. Overall capability: reliable local root escalation on vulnerable Linux kernels with AF_VSOCK and io_uring support, using a data-only page-cache/PT_INTERP hijack against /usr/bin/su rather than kernel code execution. The exploit is operational because it contains a complete end-to-end payload chain and automated shell handoff.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.