Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm IPC Router (QRTR) networking component. This component is responsible for managing communication between different processors on a device. An exploit could lead to a system crash or potentially allow unauthorized access to memory, impacting the stability and security of the affected system.
Technical details
A race condition exists in net/qrtr/af_qrtr.c within the qrtr_port_remove() function. The root cause is a violation of the RCU (Read-Copy-Update) paradigm where the socket reference count is decremented via __sock_put() before the port is removed from the qrtr_ports XArray and before the RCU grace period expires. This allows concurrent RCU readers, such as qrtr_reset_ports() or qrtr_port_lookup(), to obtain a pointer to a socket and attempt to increment the reference count of an object already marked for deletion. This can result in refcount saturation or a use-after-free (UAF) scenario. The fix involves deferring the reference count decrement until after the XArray erasure and RCU synchronization are complete.
Affected products
- Linux Linux Kernel bdabad3e363d to 2aa4c12723fe432e623462a3be42a197a128722b
Timeline
- 2026-06-04: disclosed: Patch submitted by Mingyu Wang
- 2026-06-19: patched: Commits merged into stable branches by Greg Kroah-Hartman
- 2026-06-24: advisory: CVE-2026-52947 published
References
- https://git.kernel.org/stable/c/03bfa95e452e2b6ccd76a332060ae4feaf5ad84d
- https://git.kernel.org/stable/c/2047c2aa0963bb2872fd722300a15bcb441a4c00
- https://git.kernel.org/stable/c/2aa4c12723fe432e623462a3be42a197a128722b
- https://git.kernel.org/stable/c/3b20ec8f31e8a6a6782243f473b0abd3463621df
- https://git.kernel.org/stable/c/474293d90880622fde9d2430fb0165767090f7b3
- https://git.kernel.org/stable/c/7de2d447072be3b1a76793f034432338fc9c494b
- https://git.kernel.org/stable/c/a2171131ecda1ed61a594a1eb715e75fdad0fef5