Executive brief
A data race vulnerability was identified in the Linux kernel's audit subsystem, which is responsible for logging security-relevant events. Under specific conditions, the system might incorrectly calculate the number of pending audit messages, potentially leading to inaccurate backlog reporting or minor logging delays. This is a low-impact technical issue that does not directly allow for data theft or unauthorized access.
Technical details
A data race exists in kernel/audit.c due to multiple readers accessing audit_queue.qlen via skb_queue_len() without proper synchronization. While the writer (kauditd) uses WRITE_ONCE() protected by a spinlock during skb_dequeue(), readers such as audit_log_start() and audit_receive() perform unsynchronized reads. This can result in KCSAN-detected data races during backlog checks and message processing. The vulnerability is resolved by migrating affected call sites to use the skb_queue_len_lockless() helper, which implements proper READ_ONCE() semantics to pair with the writer side.
Affected products
- Linux Linux 3197542482df22c2a131d4a813280bd7c54cedf5
Timeline
- 2026-06-19: other: Patch authored
- 2026-07-24: patched: Patch committed to stable tree
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/69f98fff30bdaa72b0cb0e7e078ab6456a0a59b0
- https://git.kernel.org/stable/c/7ff42312ccde549f8c698723822c7db35107a39b
- https://git.kernel.org/stable/c/a3d85dec60bb0622360fc176b2a51abdbe2ff0ad
- https://git.kernel.org/stable/c/b35597bdae1a5d8395da4b9baa993b9b71f74d68
- https://git.kernel.org/stable/c/c5186201fa7030289cc4fe23fae87a3fcb566856
- https://git.kernel.org/stable/c/c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7
- https://git.kernel.org/stable/c/e575dabb805252e3113fdc3f56f6ecacfde422d0