Executive brief
A vulnerability in the Linux kernel's Inter-Process Communication (IPC) system could allow a local attacker to cause a system crash or potentially access sensitive memory. The issue occurs during specific system backup or migration tasks (checkpoint/restore) where the system fails to properly limit the range of internal identifiers. This can lead to a 'use-after-free' scenario where the system attempts to access data that has already been deleted, impacting system stability and reliability.
Technical details
A vulnerability exists in ipc_idr_alloc() within the Linux kernel's checkpoint/restore sysctl path. When requesting a specific next SysV IPC ID via ids->next_id, the kernel forwards the request to idr_alloc() with an open-ended upper bound (zero). If the valid ID space is exhausted, the allocation can exceed the ipc_mni limit. Because the resulting ID is encoded with a narrower index width, subsequent removal operations via ipc_rmid() truncate the index, targeting the wrong slot. This leaves a dangling pointer in the IDR table; for shared memory (SHM), a subsequent walk of /proc/sysvipc/shm will dereference this freed memory, resulting in a use-after-free. The fix involves explicitly bounding the idr_alloc() call to ipc_mni.
Affected products
- Linux Linux Kernel 03f595668017 to 3bbe2bb9111ce6967a951bfac79af142d816fae5
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://git.kernel.org/stable/c/157ce2c6836ce0ff19108a819f38df061345425f
- https://git.kernel.org/stable/c/3bbe2bb9111ce6967a951bfac79af142d816fae5
- https://git.kernel.org/stable/c/41058d4c3f63ab64901560a704882e0565f4e456
- https://git.kernel.org/stable/c/8c58a92849175f5e2ab7bc2734b3b89afe79f6ef
- https://git.kernel.org/stable/c/a3cc795129e5ec0f8948653a3bf471e7d8852f5e
- https://git.kernel.org/stable/c/af24e202b543ded8a34f1d5d3db54eb916173f04
- https://git.kernel.org/stable/c/bd4be70669af55b974860d13680348cfdf50bbed