Junglewise Threat Intelligence

CVE-2026-74270: Linux kernel handshake privilege escalation in DONE command

CVE-2026-74270 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's handshake subsystem handles TLS negotiation requests via a kernel API used by the system's TLS daemon. An unprivileged user can forge handshake completion messages (DONE commands) without authentication, allowing them to trick the kernel into treating failed or uninitialized TLS connections as successful. This could lead to plaintext communication being accepted as encrypted or legitimate connections being abruptly terminated by a malicious user.

Technical details

A missing privilege check in the handshake_nl_done_doit() function within the Linux kernel's generic netlink (genl) family allows unprivileged processes to submit spoofed DONE commands. The vulnerability exists because the function only validates that a pending handshake request exists for a given socket file descriptor but does not authenticate the sender. An attacker who can observe or guess a valid socket fd can submit a DONE message with status 0 (success), causing the kernel consumer to proceed as if the handshake succeeded, or submit a non-zero status to tear down a legitimate in-flight handshake. The fix adds GENL_ADMIN_PERM flag requirement to the DONE command handler, restricting it to privileged processes only. Patches have been applied to stable kernel branches.

Affected products

  • Linux Linux kernel versions with net/handshake subsystem (5.13+) prior to patched 2026-06 commits

Timeline

  • 2026-08-15: disclosed
  • 2026-06-09: patched: Fix committed upstream; backported to stable branches

References

Related threats