Executive brief
A vulnerability was identified in the Linux kernel's handshake service, which manages secure connection requests. When a network namespace (a container-like isolation feature) is closed, the system fails to properly clean up pending connection requests. This can lead to memory leaks and resource exhaustion, potentially impacting system stability or preventing the reuse of network resources.
Technical details
A logic error in 'handshake_net_exit()' caused 'list_splice_init()' to be called with reversed arguments, resulting in pending handshake requests not being torn down when a network namespace is destroyed. This leaves dangling references on socket files and 'handshake_req' allocations. Furthermore, fixing the splice direction revealed a race condition where 'handshake_req_cancel()' could concurrently modify the list during the drain process, leading to list corruption or use-after-free scenarios. The fix ensures correct list splicing, implements a 'HANDSHAKE_F_NET_DRAINING' flag to prevent concurrent cancellation during cleanup, and properly pins request files to ensure they are not freed prematurely.
Affected products
- Linux Linux 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory