Race condition in Linux kernel - CVE-2026-90235
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to trigger invocation of stale socket callbacks.
The vulnerability exists due to improper synchronization in SUNRPC xprtsock socket callback handling when concurrent socket callback handling occurs during teardown. A remote attacker can race callback processing with socket teardown to trigger invocation of stale socket callbacks.
The issue applies when SUNRPC takes over AF_LOCAL, UDP, or TCP sockets.
Affected software
How to mitigate CVE-2026-90235
External References
- https://git.kernel.org/stable/c/33930840b5f0a79f826e7c69dc6cd78f72a67481
- https://git.kernel.org/stable/c/589f761236e05ff9de1bdfd6a5258f113e6457fe
- https://git.kernel.org/stable/c/d8f0b83753809761a560c4b33249388548ba6e43
- https://git.kernel.org/stable/c/da652cb17f9faeea1fa44b7215e8869a0b10b664
- https://git.kernel.org/stable/c/ed80d009b154aa204f541d390884851b3d4f15ae