Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-68141

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/af_iucv: fix NULL deref in afiucv_hs_callback_syn()<br /> <br /> afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC.<br /> If the allocation fails, nsk is NULL.<br /> <br /> The connection-refused path is entered when the listen state check<br /> fails, the accept backlog is full, or nsk is NULL. The code<br /> unconditionally calls iucv_sock_kill(nsk) in that path.<br /> <br /> iucv_sock_kill() does not accept a NULL socket pointer and immediately<br /> dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL,<br /> calling iucv_sock_kill(nsk) results in a NULL pointer dereference.<br /> <br /> Only call iucv_sock_kill() when a child socket was successfully<br /> allocated.