In the Linux kernel, the following vulnerability has been resolved:
rxrpc: serialize kernel accept preallocation with socket teardown
rxrpc_kernel_charge_accept() reads rx->backlog without any
socket/backlog synchronization and passes that raw pointer into
rxrpc_service_prealloc_one(). A concurrent rxrpc_discard_prealloc()
sets rx->backlog = NULL and frees the backlog rings, so a kernel
preallocation worker can keep using a freed struct rxrpc_backlog
while updating *_backlog_head/tail and array slots.
Serialize the state check and backlog lookup with the socket lock,
and reject kernel preallocation once teardown has disabled
listening or discarded the service backlog.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 06:22
Updated : 2026-08-23 13:16
NVD link : CVE-2026-74436
Mitre link : CVE-2026-74436
CVE.ORG link : CVE-2026-74436
JSON object : View
Products Affected
No product.
CWE
No CWE.
