CVE-2026-52946
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling<br />
<br />
A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in<br />
send_sigio() and send_sigurg() when a process group receives a signal.<br />
<br />
When FASYNC is configured for a process group (PIDTYPE_PGID), both<br />
functions use read_lock(&tasklist_lock) to traverse the task list.<br />
However, they are frequently called from softirq context:<br />
- send_sigio() via input_inject_event -> kill_fasync<br />
- send_sigurg() via tcp_check_urg -> sk_send_sigurg (NET_RX_SOFTIRQ)<br />
<br />
The deadlock is caused by the rwlock writer fairness mechanism:<br />
1. CPU 0 (process context) holds read_lock(&tasklist_lock) in do_wait().<br />
2. CPU 1 (process context) attempts write_lock(&tasklist_lock) in<br />
fork() or exit() and spins, which blocks all new readers.<br />
3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).<br />
4. The softirq calls send_sigurg() and attempts to acquire<br />
read_lock(&tasklist_lock), deadlocking because CPU 1 is waiting.<br />
<br />
Since PID hashing and do_each_pid_task() traversals are already<br />
RCU-protected, the read_lock on tasklist_lock is no longer strictly<br />
required for safe traversal. Fix this by replacing tasklist_lock with<br />
rcu_read_lock(), aligning the process group signaling path with the<br />
single-PID path. This also mitigates a potential remote denial of<br />
service vector via TCP URG packets.<br />
<br />
Lockdep splat:<br />
=====================================================<br />
WARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected<br />
[...]<br />
Chain exists of:<br />
&dev->event_lock --> &f_owner->lock --> tasklist_lock<br />
<br />
Possible interrupt unsafe locking scenario:<br />
CPU0 CPU1<br />
---- ----<br />
lock(tasklist_lock);<br />
local_irq_disable();<br />
lock(&dev->event_lock);<br />
lock(&f_owner->lock);<br />
<br />
lock(&dev->event_lock);<br />
<br />
*** DEADLOCK ***
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.12.1 (incluyendo) | 5.10.259 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (incluyendo) | 5.15.210 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.176 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.143 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.94 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.36 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.13 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.1 (incluyendo) | 7.1.1 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/00633c4683828acd5256fa8d5163f440d74bbe71
- https://git.kernel.org/stable/c/1bee417678f1135e35b25a37734db46aa94258d2
- https://git.kernel.org/stable/c/20a93e397abe850c49b6fa0e8cc827b5f634a8f5
- https://git.kernel.org/stable/c/32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33
- https://git.kernel.org/stable/c/36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed
- https://git.kernel.org/stable/c/54626335ea4174ab2d9a183b511d825f6765e47b
- https://git.kernel.org/stable/c/897d6a7247739fb1528f98c575df4f2e5de7f994
- https://git.kernel.org/stable/c/b5fa9e32fb6718f70c986ee14dd5d01b4846f331
- https://git.kernel.org/stable/c/bfcc8e8d8a495bb34cae9e620adfb75fb13a3954



