8.8

CVE-2026-68397

net/iucv: take a reference on the socket found in afiucv_hs_rcv()

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: take a reference on the socket found in afiucv_hs_rcv()

afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).

Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3881ac441f642d56503818123446f7298442236b
Version < 5739be5c19495d709d902a2912c9102ce78740d5
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < bc6c6e546ffff8865daaeb622ef348c2d481e80f
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < e3e0679fc950191aff8f27fa78abcfc2462cff4a
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < 4dc0e63abf8bc7ba8892e617c1fb8b204361e022
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < 1801cb20a5025a787d6853e19c38db138344b4b4
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < c75a950e77356e526672cba4584080c6c8b793b6
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < 5595ea59cdf29182cf6a270cacc1426c57b603de
Status affected
Version 3881ac441f642d56503818123446f7298442236b
Version < 4fa349156043dc119721d067329714179f501749
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.2
Status affected
Version 0
Version < 3.2
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.186
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022
https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4
https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6
https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de
https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749
https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5
https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f
https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a