8.8

CVE-2026-68140

net/iucv: fix use-after-free of a severed iucv_path

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: fix use-after-free of a severed iucv_path

af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path.  When the peer
severs the connection, iucv_sever_path() frees that path with
iucv_path_free() but leaves the notifications queued.  A later recvmsg()
drains message_q via iucv_process_message_q() and hands the stale path to
message_receive() -- a use-after-free of the freed iucv_path.

Drop the queued notifications when the path is severed; once the path is
gone they can no longer be received.  This also frees the notifications
leaked when a socket is closed with messages still queued.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < 5f08c5e50bcb4680069bd3f9edd5728308816ded
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < c24faf11bd31bfe0500aca12cbdd5a573a954a5d
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < 99ddb33748698296a6f17b9b34aa3d16a406bb3c
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < 23658b350b4107e8292045c2044983fd426fa15d
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < a5bbaddf69853117f28173c3f5c8fc14c6b2ec82
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < 900cd6d8119b7f3ae5c4bf82f922ff5957df43db
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < f579582c03ed526281a8450159baf1d35099a85f
Status affected
Version f0703c80e5156406ad947cb67fe277725b48080f
Version < be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.24
Status affected
Version 0
Version < 2.6.24
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.202
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d
https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82
https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db
https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f
https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a
https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded
https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c
https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d