Executive brief
A vulnerability in the Linux kernel's networking handshake component could allow a local attacker to cause a system deadlock. This issue occurs when certain network state changes trigger a conflict between different processing contexts on the same CPU. If exploited, this would result in a denial of service, causing the affected system to become unresponsive and requiring a reboot.
Technical details
A deadlock vulnerability exists in the Linux kernel's net/handshake component. The root cause is the use of plain spin_lock() instead of spin_lock_bh() for hn_lock in handshake_req_cancel(). When nvmet_tcp_state_change() is invoked in a Bottom Half (BH) context, it can reach the cancellation path; if a process-context thread on the same CPU already holds the lock, a deadlock occurs. This specifically affects the NVMe-over-TCP target when using TLS handshakes. The fix involves converting all hn_lock acquisitions to use spin_lock_bh/spin_unlock_bh to ensure softirqs are disabled during lock holding. Patch availability is confirmed in stable kernel releases 6.12.93, 6.18.35, and 7.0.12.
Affected products
- Linux Linux Kernel 6.7 to 6.12.93, 6.18.35, 7.0.12
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory