Junglewise Threat Intelligence

CVE-2026-64435: Linux Kernel data race in audit queue length handling

CVE-2026-64435 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A data race vulnerability was identified in the Linux kernel's audit subsystem, which is responsible for logging security-relevant events. Under specific conditions, the system might incorrectly calculate the number of pending audit messages, potentially leading to inaccurate backlog reporting or minor logging delays. This is a low-impact technical issue that does not directly allow for data theft or unauthorized access.

Technical details

A data race exists in kernel/audit.c due to multiple readers accessing audit_queue.qlen via skb_queue_len() without proper synchronization. While the writer (kauditd) uses WRITE_ONCE() protected by a spinlock during skb_dequeue(), readers such as audit_log_start() and audit_receive() perform unsynchronized reads. This can result in KCSAN-detected data races during backlog checks and message processing. The vulnerability is resolved by migrating affected call sites to use the skb_queue_len_lockless() helper, which implements proper READ_ONCE() semantics to pair with the writer side.

Affected products

  • Linux Linux 3197542482df22c2a131d4a813280bd7c54cedf5

Timeline

  • 2026-06-19: other: Patch authored
  • 2026-07-24: patched: Patch committed to stable tree
  • 2026-07-25: disclosed: CVE published

References