Junglewise Threat Intelligence

CVE-2026-22977: Linux Kernel denial of service in sock_recv_errqueue

CVE-2026-22977 · Severity: medium · CVSS 5.5 · Published 2026-01-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component can cause a system crash (kernel panic) when specific security hardening features are enabled. This occurs when an application attempts to read error messages from a network socket, such as during timestamp reporting. While it does not directly expose data, it can be used by a local user to disrupt system availability and cause a denial-of-service.

Technical details

A usercopy hardening violation exists in 'sock_recv_errqueue' due to 'skbuff_fclone_cache' lacking a whitelisted usercopy region for the 'cb[]' field. When TCP allocates an sk_buff using 'alloc_skb_fclone()' and it is subsequently cloned and queued for error reporting (e.g., timestamping), calling 'put_cmsg()' to copy error data to userspace triggers a kernel BUG() in '__check_heap_object()'. This occurs because the memory being accessed is not explicitly marked as safe for copying to userspace. The fix involves using a local stack variable as a bounce buffer to bypass the hardening check.

Affected products

  • Linux Linux Kernel 5.11 to 5.15.198, 6.2 to 6.6, 6.13 to 6.18.6, 6.19-rc1 to 6.19-rc4

Timeline

  • 2025-12-24: patched: Initial patch authored
  • 2026-01-21: disclosed: CVE published

References

Related threats