PT-2026-64754 · Linux · Linux

CVE-2026-64523

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: Take a long-lived file reference at submit
handshake nl accept doit() needs the file pointer backing req->hr sk->sk socket to survive the window between handshake req next() and the subsequent FD PREPARE() and get file(). The submit-side sock hold() does not provide that. sk refcnt keeps struct sock alive, but struct socket is owned by sock->file: when the consumer fputs the last file reference, sock release() tears the socket down regardless of any sock hold.
Add an hr file pointer to struct handshake req and acquire an explicit reference on sock->file during handshake req submit(). handshake complete() and handshake req cancel() release the reference on the completion-bit-winning path.
The submit error path must also release the file reference, but after rhashtable insertion a concurrent handshake req cancel() can discover the request and race the error path. Gate the error-path cleanup -- sk destruct restoration, fput, and request destruction -- with test and set bit(HANDSHAKE F REQ COMPLETED), the same serialization handshake complete() and handshake req cancel() already use. When cancel has already claimed ownership, the submit error path returns without touching the request; socket teardown handles final destruction.
The accept-side dereferences are not yet retargeted; that change comes in the next patch.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64523

Affected Products

Linux