Junglewise Threat Intelligence

CVE-2026-52923: Linux Kernel use-after-free in ipc_idr_alloc via checkpoint/restore

CVE-2026-52923 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Inter-Process Communication (IPC) system could allow a local attacker to cause a system crash or potentially access sensitive memory. The issue occurs during specific system backup or migration tasks (checkpoint/restore) where the system fails to properly limit the range of internal identifiers. This can lead to a 'use-after-free' scenario where the system attempts to access data that has already been deleted, impacting system stability and reliability.

Technical details

A vulnerability exists in ipc_idr_alloc() within the Linux kernel's checkpoint/restore sysctl path. When requesting a specific next SysV IPC ID via ids->next_id, the kernel forwards the request to idr_alloc() with an open-ended upper bound (zero). If the valid ID space is exhausted, the allocation can exceed the ipc_mni limit. Because the resulting ID is encoded with a narrower index width, subsequent removal operations via ipc_rmid() truncate the index, targeting the wrong slot. This leaves a dangling pointer in the IDR table; for shared memory (SHM), a subsequent walk of /proc/sysvipc/shm will dereference this freed memory, resulting in a use-after-free. The fix involves explicitly bounding the idr_alloc() call to ipc_mni.

Affected products

  • Linux Linux Kernel 03f595668017 to 3bbe2bb9111ce6967a951bfac79af142d816fae5

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References

Related threats