CVE-2026-80521

high

Description

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a small window where unix_add_edges() publishes a new edge (B <-> B) to GC but its skb is not queued by skb_queue_tail(). If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A <-> B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B <-> B edge. X -. A <-> B -. This edge is visible ^--' ^..' but skb is not This itself is not a problem since the next GC run will judge B as dead as well and free it finally. X -. A <.> B -. ^--' ^--' However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry. Let's unlink scc_entry before freeing the vertex in unix_del_edge().

References

https://git.kernel.org/stable/c/fe198b077864feafd4aa4b33b1a5ce26f50195a2

https://git.kernel.org/stable/c/e3702470ced94fad74d71e2232f022d2eb752a6d

https://git.kernel.org/stable/c/6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33

https://git.kernel.org/stable/c/594d905195024b228c962627ae5ae7c17bd582a4

https://git.kernel.org/stable/c/2b6c2842692d08e7acaf32d1eb47f95def35f3fe

https://git.kernel.org/stable/c/1293fd69a50d188a5788b08ba3741a3e86be1608

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-66587

Details

Source: Mitre, NVD

Published: 2026-08-26

Updated: 2026-10-03

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0017