Race condition in Linux kernel - CVE-2026-52975
Published: June 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a data race in the bonding 802.3ad port-to-aggregator handling code when processing netlink requests and concurrent bonding state changes. A local user can send crafted netlink messages to trigger the race and cause a denial of service.
The issue was reported by Kernel Concurrency Sanitizer and affects access to the port->aggregator pointer in the bonding subsystem.
How to mitigate CVE-2026-52975
Sources
- https://git.kernel.org/stable/c/3b7265b3a82f40d2357c4004b26eb794a095b186
- https://git.kernel.org/stable/c/78f409fd34fe9de2b24ad8e9dca1b4608a48ed3d
- https://git.kernel.org/stable/c/ba2272be04f0cb1e74e1e355ff32ef95df280731
- https://git.kernel.org/stable/c/c169c5837525ad842df6a542facf52b6f866a519
- https://git.kernel.org/stable/c/c4f050ce06c56cfb5993268af4a5cb66ed1cd04e