Junglewise Threat Intelligence

CVE-2026-64004: Linux Kernel NULL pointer dereference in net/iucv getsockopt

CVE-2026-64004 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem specifically affecting IUCV (Inter-User Communication Vehicle) sockets. A local user could trigger a system crash (kernel panic) by exploiting a race condition during socket operations. This could lead to a denial of service, impacting the availability of the affected system.

Technical details

A race condition exists in the AF_IUCV implementation within the Linux kernel. The vulnerability occurs in the iucv_sock_getsockopt() function when handling the SO_MSGSIZE option. If a thread calls getsockopt(SO_MSGSIZE) while another thread triggers iucv_sock_close() (e.g., via recvmsg()), the hs_dev pointer may be set to NULL between the state check and the dereference of iucv->hs_dev->mtu. This results in a NULL pointer dereference (oops). The fix involves wrapping the getsockopt switch statement in lock_sock()/release_sock() to ensure atomicity against concurrent socket state changes.

Affected products

  • Linux Linux Kernel 3.4 to 6.1.176, 6.6.x, 6.9.x

Timeline

  • 2026-05-21: disclosed: Initial patch submitted by Breno Leitao
  • 2026-06-19: patched: Patch committed to stable trees
  • 2026-07-19: advisory: CVE published

References

Related threats