CVE-2026-68141

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()<br /> <br /> afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.<br /> If the allocation fails, nsk is NULL.<br /> <br /> The connection-refused path is entered when the listen state check<br /> fails, the accept backlog is full, or nsk is NULL. The code<br /> unconditionally calls iucv_sock_kill(nsk) in that path.<br /> <br /> iucv_sock_kill() does not accept a NULL socket pointer and immediately<br /> dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,<br /> calling iucv_sock_kill(nsk) results in a NULL pointer dereference.<br /> <br /> Only call iucv_sock_kill() when a child socket was successfully<br /> allocated.