7.8

CVE-2026-80521

Medienbericht

af_unix: Unlink scc_entry in unix_del_edge().

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Unlink scc_entry in unix_del_edge().

Kyle Zeng reported that GC could free a dead SCC partially.

The scenario is as follows:

   1) Create two SCCs:

       X -.   A <-> B
       ^--'

   2) Run the following concurrently:

      2-1) send() sk-B to sk-B from sk-X
      2-2) close() both A and B

At 2-1), there is a small window where unix_add_edges()
publishes a new edge (B <-> B) to GC but its skb is not queued
by skb_queue_tail().

If 2-2) completes before skb_queue_tail() and GC is triggered,
it judges A <-> B as dead, but B is not freed because GC cannot
collect the not-yet-queued skb holding the B <-> B edge.

       X -.   A <-> B -. This edge is visible
       ^--'         ^..'  but skb is not

This itself is not a problem since the next GC run will judge
B as dead as well and free it finally.

       X -.   A <.> B -.
       ^--'         ^--'

However, X's SCC forces the next GC to call unix_walk_scc_fast(),
and it iterates over A through B's scc_entry.

Let's unlink scc_entry before freeing the vertex in unix_del_edge().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5dfd283f4651d04dbb70ceb9ae5c4a30eda3c52a
Version < 2b6c2842692d08e7acaf32d1eb47f95def35f3fe
Status affected
Version de7921631ff323369aa63a4324695ab54ea4047e
Version < 6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33
Status affected
Version 4090fa373f0e763c43610853d2774b5979915959
Version < 1293fd69a50d188a5788b08ba3741a3e86be1608
Status affected
Version 4090fa373f0e763c43610853d2774b5979915959
Version < fe198b077864feafd4aa4b33b1a5ce26f50195a2
Status affected
Version 4090fa373f0e763c43610853d2774b5979915959
Version < e3702470ced94fad74d71e2232f022d2eb752a6d
Status affected
Version 4090fa373f0e763c43610853d2774b5979915959
Version < 594d905195024b228c962627ae5ae7c17bd582a4
Status affected
Version 6.1.141
Version < 6.1.189
Status affected
Version 6.6.93
Version < 6.6.158
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
23.09.2026 15:01
https://git.kernel.org/stable/c/e3702470ced94fad74d71e2232f022d2eb752a6d
https://git.kernel.org/stable/c/594d905195024b228c962627ae5ae7c17bd582a4
https://git.kernel.org/stable/c/1293fd69a50d188a5788b08ba3741a3e86be1608
https://git.kernel.org/stable/c/fe198b077864feafd4aa4b33b1a5ce26f50195a2
https://git.kernel.org/stable/c/2b6c2842692d08e7acaf32d1eb47f95def35f3fe
https://git.kernel.org/stable/c/6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33