CVE-2026-63979

Source
https://cve.org/CVERecord?id=CVE-2026-63979
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63979.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63979
Downstream
Published
2026-07-19T14:56:03.177Z
Modified
2026-07-21T03:47:45.437596201Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net/handshake: hand off the pinned file reference to accept_doit
Details

In the Linux kernel, the following vulnerability has been resolved:

net/handshake: hand off the pinned file reference to accept_doit

handshakereqnext() removes the request from the per-net pending list and drops hnlock before handshakenlacceptdoit() reads req->hrsk->sksocket and dereferences sock->file (once in FDPREPARE() and again in getfile()). In that window a consumer running tlshandshakecancel() followed by sockfdput() (svcsock_free) or _fputsync() (xsresettransport) releases sock->file. sockrelease() then runs sockorphan(), zeroing sksocket, and frees the struct socket. The accept-side code either reads NULL through sksocket or chases freed memory.

The submit-side sockhold() does not prevent this. skrefcnt protects struct sock, but struct socket and sock->file are independently refcounted via the file descriptor the consumer owns. Pinning sk leaves sock and sock->file unprotected.

Retarget the accept-side dereferences at req->hrfile, which was pinned at submit time, instead of req->hrsk->sksocket->file. Pinning on its own is not sufficient: a consumer that cancels between handshakereqnext() returning and acceptdoit reaching FDPREPARE() takes the !removepending() branch in handshakereqcancel() and drops hrfile before the accept side takes its own reference. Hand off an additional file reference inside handshakereqnext(), under hnlock, so the accept side operates on a reference that no concurrent handshakereqcancel() can revoke. FDPREPARE() consumes that handed-off reference, either by transferring it to the new fd in fdpublish() or by dropping it in the cleanup destructor on error; the explicit getfile() that previously balanced FDPREPARE() is therefore redundant and goes away.

Update handshakereqcancel_test2 and test3 to simulate the FDPREPARE() consumption with an fput() so the kunit file-count assertions stay balanced.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63979.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3b3009ea8abb713b022d94fba95ec270cf6e7eae
Fixed
c06876d4fac38f35820946ee3b1be7d7da799cd4
Fixed
f4251190e58b209999c1ba9e6d2976136a1be055

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63979.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63979.json"