Junglewise Threat Intelligence

CVE-2026-53260: Linux Kernel TCP use-after-free in reqsk_queue_hash_req

CVE-2026-53260 · Severity: info · CVSS 5.5 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's TCP networking stack when running with real-time preemption (PREEMPT_RT) enabled. This flaw could allow a remote attacker to cause a system crash or unpredictable behavior by triggering a specific sequence of network connection requests and closures. The issue stems from how the system tracks active connection requests, potentially leading to a 'use-after-free' scenario where the system attempts to access memory that has already been released.

Technical details

A race condition exists in the Linux kernel's TCP request socket handling within 'reqsk_queue_hash_req()'. On kernels with PREEMPT_RT enabled, the function could be preempted after 'mod_timer()' is called but before 'refcount_set()' initializes the socket's reference count. If a timer expires or a listener socket closes during this window, the kernel may attempt to drop the request socket, leading to a reference count underflow and a subsequent use-after-free (UAF) condition. The fix involves wrapping the timer modification and reference count initialization in 'preempt_disable_nested()' and 'preempt_enable_nested()' to ensure atomicity relative to preemption. This vulnerability primarily affects systems configured with real-time kernel features.

Affected products

  • Linux Linux Kernel PREEMPT_RT enabled versions

Timeline

  • 2026-06-01: disclosed: Initial patch submitted by Kuniyuki Iwashima
  • 2026-06-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-06-25: advisory: CVE-2026-53260 published

References

Related threats