Junglewise Threat Intelligence

CVE-2026-63979: Linux Kernel use-after-free in net/handshake during request acceptance

CVE-2026-63979 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's handshake service, which manages secure connection setups like TLS. A flaw in how the system tracks internal file references could allow a local user to trigger a system crash or unpredictable behavior by canceling a handshake at a specific moment. This primarily impacts the stability and availability of services relying on the kernel's handshake mechanism.

Technical details

A race condition exists in the Linux kernel's net/handshake implementation between handshake_req_next() and handshake_nl_accept_doit(). The vulnerability occurs because the code dereferences sock->file via sk_socket after dropping hn_lock, but before ensuring the file reference is pinned. If a consumer calls tls_handshake_cancel() and releases the socket file in this window, the accept-side code may encounter a NULL pointer or access freed memory (use-after-free). The fix involves handing off a pinned file reference (hr_file) directly within handshake_req_next() under the protection of hn_lock to ensure the reference remains valid regardless of concurrent cancellations.

Affected products

  • Linux Linux 6.4

Timeline

  • 2026-05-25: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References