Improper resource shutdown or release in Linux kernel - CVE-2026-98289

 

Improper resource shutdown or release in Linux kernel - CVE-2026-98289

Published: October 7, 2026


Vulnerability identifier: #VU153729
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98289
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to prevent garbage collection of UNIX socket resources.

The vulnerability exists due to inconsistent strongly connected component indices in the AF_UNIX garbage collector's __unix_walk_scc() function when finalising strongly connected components. A local user can trigger depth-first traversal of a UNIX socket graph containing multiple back edges to prevent garbage collection of UNIX socket resources.

The failure depends on the traversal order: vertices within the same strongly connected component can retain different lowpoint values, causing unix_vertex_dead() to incorrectly treat an edge as leading to another component.


Affected software

Linux kernel

How to mitigate CVE-2026-98289

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins