CVE-2026-53005: af_unix: Drop all SCM attributes for SOCKMAP.
afunix: Drop all SCM attributes for SOCKMAP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.0-rc7-00263-gb9d8b856689d - Compensating control
If SOCKMAP is in use, disable SOCKMAP to avoid the Tarjan-based AF_UNIX GC assumptions being violated ("SOCKMAP redirect breaks the Tarjan-based GC") and the reported SOCKMAP/AF_UNIX use-after-free conditions.
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Systems are exposed when AF_UNIX sockets and SOCKMAP are used together in a way that sends SCM attributes, particularly inflight file descriptors, through traffic redirected into a SOCKMAP. The issue is local-vector and requires low privileges according to the supplied severity vector.
What access is required to exploit the issue?
An attacker needs local access with low privileges and must be able to exercise the affected AF_UNIX and SOCKMAP interaction. No user interaction is required.
What can be done as a temporary mitigation?
If patching cannot happen immediately, limit or disable use of SOCKMAP for AF_UNIX socket traffic and prevent SCM attributes from being passed into that path where operationally possible. This reduces exposure to the redirected-SKB condition described.
How can administrators identify signs that a system is affected?
The issue may not be visible through kmemleak, because inflight sockets are linked to a global list. Relevant symptoms include AF_UNIX garbage-collection failures such as a KASAN slab use-after-free in unix_del_edges, leaked inflight sockets, or incorrect file-descriptor counts reported by unix_show_fdinfo().