Executive brief
A vulnerability in the Linux kernel's file control (fcntl) mechanism could allow a remote attacker to cause a system crash or freeze. The issue occurs when the system handles specific types of network traffic (TCP Urgent packets) or input events, leading to a 'deadlock' where the system becomes unresponsive. This primarily impacts system availability and could be used to perform a denial-of-service attack.
Technical details
A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock exists in fs/fcntl.c within the send_sigio() and send_sigurg() functions. When FASYNC is configured for a process group, these functions acquire read_lock(&tasklist_lock) to traverse tasks. Because these functions can be invoked from softirq context (e.g., via NET_RX_SOFTIRQ during TCP URG packet processing), a deadlock occurs if a writer is already spinning on the tasklist_lock in process context. An attacker can potentially trigger this remotely via TCP URG packets to cause a Denial of Service (DoS). The fix replaces the tasklist_lock with rcu_read_lock() for task list traversal, which is safe for softirq contexts.
Affected products
- Linux Linux Kernel All versions prior to the June 2026 patches
Timeline
- 2026-05-23: disclosed: Initial patch submission by Mingyu Wang
- 2026-06-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2026-06-24: advisory: CVE-2026-52946 published
References
- https://git.kernel.org/stable/c/1bee417678f1135e35b25a37734db46aa94258d2
- https://git.kernel.org/stable/c/20a93e397abe850c49b6fa0e8cc827b5f634a8f5
- https://git.kernel.org/stable/c/32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33
- https://git.kernel.org/stable/c/36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed
- https://git.kernel.org/stable/c/54626335ea4174ab2d9a183b511d825f6765e47b
- https://git.kernel.org/stable/c/897d6a7247739fb1528f98c575df4f2e5de7f994
- https://git.kernel.org/stable/c/b5fa9e32fb6718f70c986ee14dd5d01b4846f331