๐Ÿ” CVE Alert

CVE-2026-68140

HIGH 8.8

net/iucv: fix use-after-free of a severed iucv_path

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path af_iucv queues not-yet-received message notifications on iucv->message_q, each holding a raw pointer to the connection's iucv_path. When the peer severs the connection, iucv_sever_path() frees that path with iucv_path_free() but leaves the notifications queued. A later recvmsg() drains message_q via iucv_process_message_q() and hands the stale path to message_receive() -- a use-after-free of the freed iucv_path. Drop the queued notifications when the path is severed; once the path is gone they can no longer be received. This also frees the notifications leaked when a socket is closed with messages still queued.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
f0703c80e5156406ad947cb67fe277725b48080f < 5f08c5e50bcb4680069bd3f9edd5728308816ded f0703c80e5156406ad947cb67fe277725b48080f < c24faf11bd31bfe0500aca12cbdd5a573a954a5d f0703c80e5156406ad947cb67fe277725b48080f < 99ddb33748698296a6f17b9b34aa3d16a406bb3c f0703c80e5156406ad947cb67fe277725b48080f < 23658b350b4107e8292045c2044983fd426fa15d f0703c80e5156406ad947cb67fe277725b48080f < a5bbaddf69853117f28173c3f5c8fc14c6b2ec82 f0703c80e5156406ad947cb67fe277725b48080f < 900cd6d8119b7f3ae5c4bf82f922ff5957df43db f0703c80e5156406ad947cb67fe277725b48080f < f579582c03ed526281a8450159baf1d35099a85f f0703c80e5156406ad947cb67fe277725b48080f < be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a
Linux / Linux
2.6.24

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded git.kernel.org: https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d git.kernel.org: https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c git.kernel.org: https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d git.kernel.org: https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82 git.kernel.org: https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db git.kernel.org: https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f git.kernel.org: https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a