Use-after-free in Linux kernel - CVE-2026-64109
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in unix_stream_data_wait() in net/unix/af_unix.c when processing racing recv() operations on the same AF_UNIX stream socket. A local user can trigger concurrent peek and normal receive operations to cause a denial of service.
Exploitation requires a race condition between a peeking recv() call and a normal recv() call on the same socket.
How to mitigate CVE-2026-64109
Sources
- https://git.kernel.org/stable/c/26342087fac93b3932e6af61dc91ec029cb8a623
- https://git.kernel.org/stable/c/38bccb927d83d7d52e5b20015a172a0b6101d11e
- https://git.kernel.org/stable/c/5f162f95a95834f06a8ec6140889272ad12e842f
- https://git.kernel.org/stable/c/acdff9907478e82208475b1151700d0b71dcdc63
- https://git.kernel.org/stable/c/be309f8eae8b474a4a617eaae01324da996fc719