CVE-2026-68397
Received Received - Intake

Memory Corruption in Linux Kernel IUCV Socket Handling

Vulnerability report for CVE-2026-68397, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock, drops the lock, and then passes the socket to the afiucv_hs_callback_*() handlers without holding a reference. AF_IUCV sockets are not RCU-protected and are freed synchronously by iucv_sock_kill() -> sock_put(), so a concurrent close can free the socket in the window between read_unlock() and the handler, which then dereferences freed memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()). Take a reference with sock_hold() while the socket is still on the list and release it with sock_put() once the handler has run.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's AF_IUCV (Inter-User Communication Vehicle) socket implementation. The issue occurs in afiucv_hs_rcv() where a socket is looked up under a lock, the lock is released, and then the socket is passed to a callback handler without holding a reference. If the socket is closed concurrently, it can be freed before the handler runs, causing the handler to dereference freed memory.

Detection Guidance

This vulnerability affects the Linux kernel's AF_IUCV socket handling. Detection requires checking kernel versions and examining kernel logs for related crashes or memory corruption events. Commands like 'uname -a' to check kernel version and 'dmesg | grep iucv' to inspect kernel logs may help identify affected systems.

Impact Analysis

This vulnerability could allow an attacker to cause a denial-of-service (system crash) or potentially execute arbitrary code with kernel privileges. It affects systems using AF_IUCV sockets, which are primarily used for communication between z/VM guests on IBM Z systems.

Mitigation Strategies

Apply the latest kernel patches or updates that address this issue. If immediate patching is not possible, consider disabling AF_IUCV sockets if not required, or restrict network access to systems using this protocol to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68397. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart