๐Ÿ” CVE Alert

CVE-2026-80521

HIGH 7.8

af_unix: Unlink scc_entry in unix_del_edge().

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a small window where unix_add_edges() publishes a new edge (B <-> B) to GC but its skb is not queued by skb_queue_tail(). If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A <-> B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B <-> B edge. X -. A <-> B -. This edge is visible ^--' ^..' but skb is not This itself is not a problem since the next GC run will judge B as dead as well and free it finally. X -. A <.> B -. ^--' ^--' However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry. Let's unlink scc_entry before freeing the vertex in unix_del_edge().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 26, 2026
Last Updated Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
5dfd283f4651d04dbb70ceb9ae5c4a30eda3c52a < 2b6c2842692d08e7acaf32d1eb47f95def35f3fe de7921631ff323369aa63a4324695ab54ea4047e < 6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33 4090fa373f0e763c43610853d2774b5979915959 < 1293fd69a50d188a5788b08ba3741a3e86be1608 4090fa373f0e763c43610853d2774b5979915959 < fe198b077864feafd4aa4b33b1a5ce26f50195a2 4090fa373f0e763c43610853d2774b5979915959 < e3702470ced94fad74d71e2232f022d2eb752a6d 4090fa373f0e763c43610853d2774b5979915959 < 594d905195024b228c962627ae5ae7c17bd582a4 6.1.141 < 6.1.189 6.6.93 < 6.6.158
Linux / Linux
6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2b6c2842692d08e7acaf32d1eb47f95def35f3fe git.kernel.org: https://git.kernel.org/stable/c/6fda5c51b8e43a8440f76e65c89d9f95ddb2ef33 git.kernel.org: https://git.kernel.org/stable/c/1293fd69a50d188a5788b08ba3741a3e86be1608 git.kernel.org: https://git.kernel.org/stable/c/fe198b077864feafd4aa4b33b1a5ce26f50195a2 git.kernel.org: https://git.kernel.org/stable/c/e3702470ced94fad74d71e2232f022d2eb752a6d git.kernel.org: https://git.kernel.org/stable/c/594d905195024b228c962627ae5ae7c17bd582a4