7.8

CVE-2026-74270

handshake: Require admin permission for DONE command

In the Linux kernel, the following vulnerability has been resolved:

handshake: Require admin permission for DONE command

ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE has
no privilege check at all.

The fd-lookup in handshake_nl_done_doit() only confirms that
some pending handshake request exists for the supplied sockfd;
it does not authenticate the sender. An unprivileged process
that guesses or observes a valid sockfd can therefore submit
a DONE with HANDSHAKE_A_DONE_STATUS == 0, leaving the kernel
consumer to proceed as if the handshake succeeded. A non-zero
status on a forged DONE tears down a legitimate in-flight
handshake before tlshd can report its real result.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Version < 25fb53e43ec006ac69b9e825a7e8a11d63a6083e
Status affected
Version 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Version < b6557f912509abe8e70223373dd7a44d1d4a0d6c
Status affected
Version 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Version < 67cec2f1eb9e58719d622e92e2278ceda72dbd85
Status affected
Version 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Version < 4dafc411948469277b276724c3b2b4408c02c04c
Status affected
Version 3b3009ea8abb713b022d94fba95ec270cf6e7eae
Version < 81246a65303d9635266b1334490142caaf86a11f
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version 0
Version < 6.4
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/25fb53e43ec006ac69b9e825a7e8a11d63a6083e
https://git.kernel.org/stable/c/b6557f912509abe8e70223373dd7a44d1d4a0d6c
https://git.kernel.org/stable/c/67cec2f1eb9e58719d622e92e2278ceda72dbd85
https://git.kernel.org/stable/c/4dafc411948469277b276724c3b2b4408c02c04c
https://git.kernel.org/stable/c/81246a65303d9635266b1334490142caaf86a11f