Executive brief
A vulnerability has been identified in the Linux kernel's Kernel Connection Multiplexor (KCM), a component used to improve network application performance. A race condition could allow a local attacker to cause a system crash or potentially execute unauthorized actions by triggering a timing flaw during the disconnection of network sockets. This issue primarily impacts system stability and availability.
Technical details
A race condition exists in the Linux kernel's Kernel Connection Multiplexor (KCM) module when kcm_unattach() and kcm_release() are executed concurrently. The vulnerability stems from kcm_unattach() failing to check the tx_stopped flag before calling queue_work(), which allows kcm->tx_work to be requeued after it has been synchronized but before the KCM structure is freed in kcm_done(). This leads to a use-after-free (UAF) condition. The fix replaces the manual flag check with disable_work_sync() to properly fence the workqueue. Local attackers with sufficient privileges to interact with KCM sockets can exploit this to cause a kernel panic or potentially achieve local privilege escalation.
Affected products
- Linux Linux Kernel 4.6 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1
Timeline
- 2025-08-13: patched: Initial fix commit in mainline kernel
- 2025-09-04: disclosed: CVE published