CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv()
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: take a reference on the socket found in afiucvhsrcv()
afiucvhsrcv() looks up the destination socket under iucvsklist.lock, drops the lock, and then passes the socket to the afiucvhscallback() handlers without holding a reference. AFIUCV sockets are not RCU-protected and are freed synchronously by iucvsockkill() -> sockput(), so a concurrent close can free the socket in the window between readunlock() and the handler, which then dereferences freed memory (for example sk->skdataready() in afiucvhscallbacksyn()).
Take a reference with sockhold() while the socket is still on the list and release it with sockput() once the handler has run.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68397?
CVE-2026-68397 has a risk score of 46, indicating a medium severity vulnerability.
How do I fix CVE-2026-68397?
To fix CVE-2026-68397, update the Linux kernel to the latest version where the vulnerability has been addressed.
What systems are affected by CVE-2026-68397?
CVE-2026-68397 affects various versions of the Linux kernel that utilize the IUCV protocol.
What is the main issue with CVE-2026-68397?
The main issue with CVE-2026-68397 is that it improperly handles socket references in the afiucv_hs_rcv() function.
Is CVE-2026-68397 exploitable?
CVE-2026-68397 may be exploitable under certain conditions, depending on the use of IUCV sockets in the affected systems.