Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue occurs when certain network drivers handle data transmission timestamps in a way that leads to a 'deadlock,' effectively freezing the system. This affects the reliability and availability of servers and workstations running impacted versions of the Linux operating system.
Technical details
A deadlock vulnerability exists in the Linux kernel networking stack within the skb_may_tx_timestamp() function. The root cause is the acquisition of sock::sk_callback_lock in an IRQ context, which is prohibited as only softirq is permitted. Certain network drivers that receive timestamps via dedicated interrupts can trigger this deadlock if the lock is already write-locked on the same CPU. The fix involves removing the lock acquisition and instead using RCU-protected pointer access with READ_ONCE() and WRITE_ONCE() to safely check socket and file members. Patches have been released for various stable branches including 6.18.x and 6.19.x.
Affected products
- Linux Linux 4.0 to 6.18.16, 6.19.6
Timeline
- 2026-02-20: other: Initial patch authored
- 2026-05-06: disclosed: CVE published
- 2026-07-04: patched: Final stable branch patches applied