CVE-2026-81003
Received Received - Intake

Buffer Overflow in Linux Kernel AF_IUCV

Vulnerability report for CVE-2026-81003, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport header alone. No check is made against the net_device the frame arrived on. This can cause a frame arriving on any netdev to be delivered to an AF_IUCV socket. Three problems follow. First, a frame arriving over HiperSockets can be delivered to a socket bound to the classic z/VM IUCV transport, which has iucv->hs_dev == NULL. iucv_sock_bind() takes the classic path whenever the requested userid matches iucv_userid, even on a guest that also has a HiperSockets device carrying the same identifier. The child socket created by afiucv_hs_callback_syn() for such a match inherits hs_dev = NULL and transport = AF_IUCV_TRANS_HIPER, so the first send() on it returns -ENODEV. The socket delivered to accept() is unusable. Second, a frame arriving on one netdev can be delivered to a socket bound to a different IQD device. Which can lead to - Accept-queue exhaustion (DoS) - Attacker-controlled peer identity in the child socket - Data injection into existing sockets - Fabric noise on the IQD fabric, where bogus replies are sent - killing established connections Third, all AF_IUCV sockets live in init_net, as iucv_sock_alloc() calls sk_alloc(&init_net, ...). But even frames arriving on netdev devices in a namespace can be delivered to an IUCV socket. So a process in an unprivileged user and network namespace holding only the CAP_NET_RAW capability valid within that namespace can send a raw ETH_P_AF_IUCV frame on its own lo device and have it matched against init_net sockets. Fix all three by skipping any socket whose hs_dev does not match the ingress device. A classic z/VM IUCV socket has hs_dev == NULL; the ingress dev is never NULL, so classic sockets are skipped automatically. An unbound HIPER socket also has hs_dev == NULL and is skipped. A bound HIPER socket is only reachable from the exact IQD device it was bound to. Because hs_dev is always a device in init_net (iucv_sock_bind() scans for_each_netdev_rcu(&init_net, ...) exclusively), a frame whose ingress device belongs to another namespace never matches any socket. Note that AF_IUCV over HiperSockets provides no per-connection authentication: no sequence numbers, no TLS, no nonce. The four name fields identifying a connection are exchanged in plaintext on the shared HiperSockets segment (VCHID). Any host on the same HiperSockets segment could spoof any frame type against an existing connection. That is a protocol-level property unchanged by this patch. The fix reduces the attack surface to peers present on the same HiperSockets segment.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the AF_IUCV socket implementation where frames are not properly filtered by the ingress network device. The function afiucv_hs_rcv() matches frames based on name fields in the transport header without checking the net_device the frame arrived on. This allows frames from any network device to be delivered to AF_IUCV sockets, leading to potential misuse such as data injection, connection disruption, or denial of service.

Detection Guidance

This vulnerability affects AF_IUCV sockets in the Linux kernel, specifically related to frame handling in afiucv_hs_rcv(). Detection requires checking kernel logs for IUCV-related errors or examining network traffic for malformed AF_IUCV frames. Use commands like 'dmesg | grep iucv' or 'journalctl -k | grep iucv' to inspect kernel logs for IUCV errors. Monitor network interfaces for unexpected AF_IUCV traffic using tools like tcpdump with filters for ETH_P_AF_IUCV frames.

Impact Analysis

This vulnerability can impact you by allowing unauthorized access to AF_IUCV sockets, enabling attackers to inject data into existing connections, disrupt services through denial of service, or spoof peer identities. It may also allow processes in restricted namespaces to interact with sockets in the init_net namespace, bypassing intended isolation.

Compliance Impact

This vulnerability primarily affects data integrity and access control in network communications. It could lead to unauthorized data access or injection, which may violate GDPR's data protection principles or HIPAA's safeguards for protected health information. The lack of per-connection authentication in AF_IUCV over HiperSockets exacerbates this risk by allowing spoofing attacks on the shared segment.

Mitigation Strategies

Apply the Linux kernel patch that resolves this issue by filtering frames in afiucv_hs_rcv() by ingress device. Ensure the kernel is updated to a version containing the fix. If immediate patching is not possible, restrict access to AF_IUCV sockets by limiting CAP_NET_RAW capabilities and isolating network namespaces. Monitor IQD fabric traffic for anomalies and disable unused AF_IUCV sockets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81003. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart