CVE-2026-68397 (GCVE-0-2026-68397)
Vulnerability from cvelistv5
Published
2026-08-10 12:04
Modified
2026-08-19 16:34
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: take a reference on the socket found in afiucv_hs_rcv()
afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,
drops the lock, and then passes the socket to the afiucv_hs_callback_*()
handlers without holding a reference. AF_IUCV sockets are not
RCU-protected and are freed synchronously by iucv_sock_kill() ->
sock_put(), so a concurrent close can free the socket in the window
between read_unlock() and the handler, which then dereferences freed
memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).
Take a reference with sock_hold() while the socket is still on the list
and release it with sock_put() once the handler has run.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b Version: 3881ac441f642d56503818123446f7298442236b |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5739be5c19495d709d902a2912c9102ce78740d5",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "bc6c6e546ffff8865daaeb622ef348c2d481e80f",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "e3e0679fc950191aff8f27fa78abcfc2462cff4a",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4dc0e63abf8bc7ba8892e617c1fb8b204361e022",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "1801cb20a5025a787d6853e19c38db138344b4b4",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "c75a950e77356e526672cba4584080c6c8b793b6",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "5595ea59cdf29182cf6a270cacc1426c57b603de",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
},
{
"lessThan": "4fa349156043dc119721d067329714179f501749",
"status": "affected",
"version": "3881ac441f642d56503818123446f7298442236b",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/iucv/af_iucv.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.148",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.101",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.42",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.6",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.265",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.216",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.183",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.148",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.101",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.42",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.6",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() -\u003e\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk-\u003esk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The vulnerable handler is registered via dev_add_pack() for ethertype ETH_P_AF_IUCV (0xFBFB) on every netdevice, so any peer LPAR/guest on the same HiperSockets internal LAN or any host on an attached Ethernet segment can drive afiucv_hs_rcv() with crafted frames; the frames are raw L2 and cannot be routed across an IP hop, so the vector is adjacent rather than network.\nAC:L - The attacker controls the packet side of the race outright (flooding 0xFBFB frames) and can drive the freeing side too, since SYN frames make a listener spawn and enqueue child sockets while FIN/SYN|FIN frames push sockets to IUCV_DISCONN and wake the application into close(), so the read_unlock()-to-handler window can be retried indefinitely until won.\nPR:N - afiucv_hs_rcv() runs from the netif RX softirq and processes any matching frame with no authentication, credential check, or capability test anywhere on the path; the attacker needs no account or privilege on the target s390 system.\nUI:N - No victim action is required: the attacker\u0027s own frames both create the AF_IUCV child sockets and trigger the state changes that lead to their teardown, and the packet handler runs unconditionally in softirq context.\nS:U - The freed struct sock and the resulting corruption stay inside the kernel of the affected LPAR or z/VM guest; no hypervisor, IOMMU, or container boundary is crossed.\nC:H - This is a use-after-free on a socket allocated from a generic kmalloc cache (iucv_proto is registered without its own slab), so an attacker who reclaims the object has the kernel read attacker-influenced or stale heap contents through sk fields, sk_filter()\u0027s BPF program pointer, and the iucv backlog queues, yielding kernel memory disclosure.\nI:H - After the free the handlers perform indirect calls through the freed object (sk-\u003esk_data_ready(), sk-\u003esk_state_change(), sk_filter()) and writes into it (sk_state, atomic_sub on iucv-\u003emsg_sent, skb_queue_tail() list-pointer updates), giving control-flow hijack and write primitives once the slab object is reclaimed with attacker-controlled data.\nA:H - Dereferencing the freed socket from softirq context reliably produces an oops or \"Fatal exception in interrupt\" panic, and the attacker can repeat the frame flood at will, causing complete loss of availability of the IBM Z LPAR or guest."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T16:34:47.433Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5739be5c19495d709d902a2912c9102ce78740d5"
},
{
"url": "https://git.kernel.org/stable/c/bc6c6e546ffff8865daaeb622ef348c2d481e80f"
},
{
"url": "https://git.kernel.org/stable/c/e3e0679fc950191aff8f27fa78abcfc2462cff4a"
},
{
"url": "https://git.kernel.org/stable/c/4dc0e63abf8bc7ba8892e617c1fb8b204361e022"
},
{
"url": "https://git.kernel.org/stable/c/1801cb20a5025a787d6853e19c38db138344b4b4"
},
{
"url": "https://git.kernel.org/stable/c/c75a950e77356e526672cba4584080c6c8b793b6"
},
{
"url": "https://git.kernel.org/stable/c/5595ea59cdf29182cf6a270cacc1426c57b603de"
},
{
"url": "https://git.kernel.org/stable/c/4fa349156043dc119721d067329714179f501749"
}
],
"title": "net/iucv: take a reference on the socket found in afiucv_hs_rcv()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-68397",
"datePublished": "2026-08-10T12:04:16.772Z",
"dateReserved": "2026-07-30T09:28:09.389Z",
"dateUpdated": "2026-08-19T16:34:47.433Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…