CVE-2026-74270: handshake: Require admin permission for DONE command
In the Linux kernel, the following vulnerability has been resolved:
handshake: Require admin permission for DONE command
ACCEPT and DONE are the two downcalls of the handshake genl family, both intended for use by the trusted handshake agent (tlshd). ACCEPT already requires GENLADMINPERM; DONE has no privilege check at all.
The fd-lookup in handshakenldonedoit() only confirms that some pending handshake request exists for the supplied sockfd; it does not authenticate the sender. An unprivileged process that guesses or observes a valid sockfd can therefore submit a DONE with HANDSHAKEADONESTATUS == 0, leaving the kernel consumer to proceed as if the handshake succeeded. A non-zero status on a forged DONE tears down a legitimate in-flight handshake before tlshd can report its real result.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Modify the netlink handshake to require GENL_ADMIN_PERM (admin permission) when processing the DONE command (handshake_nl_done_doit), so unprivileged processes cannot forge DONE to prematurely tear down legitimate in-flight handshake requests.
Linux kernel netlink handshake (handshake_nl_done_doit) Require GENL_ADMIN_PERM for DONE command = enforce
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74270?
CVE-2026-74270 has a risk rating of 47, indicating a significant vulnerability in the Linux kernel.
How do I fix CVE-2026-74270?
To remediate CVE-2026-74270, ensure that the system is updated to the patched version of the Linux kernel where the DONE command requires admin permission.
What systems are affected by CVE-2026-74270?
CVE-2026-74270 affects the Linux kernel, specifically components related to the handshake genl family.
What does the DONE command do in the context of CVE-2026-74270?
In CVE-2026-74270, the DONE command is a downcall intended for use by the trusted handshake agent, which now requires admin permissions to execute.
Why is it important to address CVE-2026-74270?
Addressing CVE-2026-74270 is crucial as it helps prevent unauthorized access and potential exploitation through the mistaken use of the DONE command without proper permissions.