Race condition in Linux kernel - CVE-2026-53361
Published: July 7, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in unix_gc() and unix_peek_fpl() in the af_unix garbage collection logic when processing MSG_PEEK operations during garbage collection scheduling. A local user can trigger concurrent garbage collection activity to cause a denial of service.
The issue occurs because gc_in_progress may be false while unix_gc() is running, which can confuse garbage collection by MSG_PEEK.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-53361
linux (Debian package) - update to 6.12.95-1