Junglewise Threat Intelligence

CVE-2026-52930: Linux Kernel race condition in ipc/shm orphan cleanup

CVE-2026-52930 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's shared memory (SHM) subsystem. This component allows different programs to share the same memory space for faster data exchange. Under specific conditions, the system might incorrectly clean up a memory segment that is still in use, potentially leading to system instability or crashes.

Technical details

A race condition exists in ipc/shm.c within the Linux kernel. The function shm_destroy_orphaned() iterates through shared memory identifiers using the namespace rwsem, but it fails to properly synchronize with shm_nattch (attachment count) updates which occur under shm_perm.lock. Because attach paths can update the attachment count without holding the rwsem, shm_may_destroy() could return true prematurely. This allows a shared memory segment to be destroyed while a concurrent process is attempting to attach to it. The fix moves the shm_may_destroy() check inside the shm_perm.lock critical section to ensure atomic evaluation of the segment's state.

Affected products

  • Linux Linux 3.1 to 5.10.259, 5.15.210, and other stable branches

Timeline

  • 2026-04-30: other: Vulnerability fix authored
  • 2026-06-03: other: Patch committed to maintainer tree
  • 2026-06-24: disclosed: CVE published and patched in stable branches

References