Executive brief
A vulnerability was identified in the Linux kernel's Phonet network protocol implementation that could allow a local attacker to cause a system crash or deadlock. The issue occurs when the system handles specific network packets in a way that creates conflicting internal locking states. This primarily impacts the availability of the system, potentially leading to a denial-of-service condition.
Technical details
A vulnerability exists in net/phonet/pep.c due to inconsistent bottom-half (BH) execution contexts when calling sk_receive_skb(). While the networking receive path typically runs in softirq context with BH disabled, pep_do_rcv() can be reached from process context via release_sock() with BH enabled. When forwarding a socket buffer (skb) to a child socket, the code acquires the child socket's spinlock without ensuring BH is disabled, leading to a potential deadlock if a softirq interrupts the process context while the lock is held. The fix involves wrapping the sk_receive_skb() call in local_bh_disable() and local_bh_enable() to ensure consistent locking state.
Affected products
- Linux Linux kernel Fixed in various stable branches including 6.1.y and others via commit dbc81608e3a653dea6cf403f20cae35468b8ab9c
Timeline
- 2026-05-19: patched: Initial fix authored
- 2026-07-19: advisory: CVE-2026-64177 published
References
- https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212
- https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3
- https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37
- https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e
- https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53
- https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b
- https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c