Executive brief
A vulnerability was identified in the Linux kernel's networking subsystem specifically affecting IUCV (Inter-User Communication Vehicle) sockets. A local user could trigger a system crash (kernel panic) by exploiting a race condition during socket operations. This could lead to a denial of service, impacting the availability of the affected system.
Technical details
A race condition exists in the AF_IUCV implementation within the Linux kernel. The vulnerability occurs in the iucv_sock_getsockopt() function when handling the SO_MSGSIZE option. If a thread calls getsockopt(SO_MSGSIZE) while another thread triggers iucv_sock_close() (e.g., via recvmsg()), the hs_dev pointer may be set to NULL between the state check and the dereference of iucv->hs_dev->mtu. This results in a NULL pointer dereference (oops). The fix involves wrapping the getsockopt switch statement in lock_sock()/release_sock() to ensure atomicity against concurrent socket state changes.
Affected products
- Linux Linux Kernel 3.4 to 6.1.176, 6.6.x, 6.9.x
Timeline
- 2026-05-21: disclosed: Initial patch submitted by Breno Leitao
- 2026-06-19: patched: Patch committed to stable trees
- 2026-07-19: advisory: CVE published
References
- https://git.kernel.org/stable/c/1fc30bd4e55e2dd622d2d366cecd732c1841bbee
- https://git.kernel.org/stable/c/3589d20a666caf30ad100c960a2de7de390fce88
- https://git.kernel.org/stable/c/45bb8de8c95d8899f4b8f61bd9bceb8132af73cb
- https://git.kernel.org/stable/c/69554adc7a6fa04ede3ad7512321d83748e3c920
- https://git.kernel.org/stable/c/6e792b8dd3002bbc4136745928a9605df1a72b8a
- https://git.kernel.org/stable/c/884eb247b74d86db97e3a37f0d6fc8e1e83590dd
- https://git.kernel.org/stable/c/9817369243380e287ebe5525411557eaa3aa2a79