Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-52946

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling<br /> <br /> A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in<br /> send_sigio() and send_sigurg() when a process group receives a signal.<br /> <br /> When FASYNC is configured for a process group (PIDTYPE_PGID), both<br /> functions use read_lock(&amp;tasklist_lock) to traverse the task list.<br /> However, they are frequently called from softirq context:<br /> - send_sigio() via input_inject_event -&gt; kill_fasync<br /> - send_sigurg() via tcp_check_urg -&gt; sk_send_sigurg (NET_RX_SOFTIRQ)<br /> <br /> The deadlock is caused by the rwlock writer fairness mechanism:<br /> 1. CPU 0 (process context) holds read_lock(&amp;tasklist_lock) in do_wait().<br /> 2. CPU 1 (process context) attempts write_lock(&amp;tasklist_lock) in<br /> fork() or exit() and spins, which blocks all new readers.<br /> 3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).<br /> 4. The softirq calls send_sigurg() and attempts to acquire<br /> read_lock(&amp;tasklist_lock), deadlocking because CPU 1 is waiting.<br /> <br /> Since PID hashing and do_each_pid_task() traversals are already<br /> RCU-protected, the read_lock on tasklist_lock is no longer strictly<br /> required for safe traversal. Fix this by replacing tasklist_lock with<br /> rcu_read_lock(), aligning the process group signaling path with the<br /> single-PID path. This also mitigates a potential remote denial of<br /> service vector via TCP URG packets.<br /> <br /> Lockdep splat:<br /> =====================================================<br /> WARNING: SOFTIRQ-safe -&gt; SOFTIRQ-unsafe lock order detected<br /> [...]<br /> Chain exists of:<br /> &amp;dev-&gt;event_lock --&gt; &amp;f_owner-&gt;lock --&gt; tasklist_lock<br /> <br /> Possible interrupt unsafe locking scenario:<br /> CPU0 CPU1<br /> ---- ----<br /> lock(tasklist_lock);<br /> local_irq_disable();<br /> lock(&amp;dev-&gt;event_lock);<br /> lock(&amp;f_owner-&gt;lock);<br /> <br /> lock(&amp;dev-&gt;event_lock);<br /> <br /> *** DEADLOCK ***

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.12.1 (incluyendo) 5.10.259 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.210 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.176 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.143 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.94 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.36 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.13 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 7.1 (incluyendo) 7.1.1 (excluyendo)
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*