af_unix: Update last skb marker in manage_oob().
Summary
| CVE | CVE-2026-97985 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:26 UTC |
| Updated | 2026-09-25 11:17:26 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog CPU due to OOB skb. In the following cases, manage_oob() skips OOB skb(s) and returns NULL for the last recv(MSG_PEEK): socketpair(AF_UNIX, SOCK_STREAM, 0, sk); 1) skb -> OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK); 2) skb -> consumed OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 1, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK); 3) consumed OOB skb -> OOB skb -> NULL send(sk[0], "a", 1, MSG_OOB); recv(sk[1], buf, 0, MSG_OOB); send(sk[0], "b", 1, MSG_OOB); recv(sk[1], buf, 1, MSG_PEEK); Then, @copied is 0 in unix_stream_read_generic() (zero-length buffer, or non-OOB skb is not yet consumed), and unix_stream_data_wait() is called. However, it returns immediately because @last is not updated in unix_stream_read_generic(), and the thread busy-waits for a new skb. Let's update @last in manage_oob(). For MSG_PEEK, @last is updated with the skipped OOB, and for the non-peek case, @last matches the returned value (when !copied) because OOB is unlinked. Note that manage_oob() is inlined and no stack canary is added. |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.053960000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 22dd70eb2c3d754862964377a75abafd3167346b 0630bfc773d85ac44da05b2c5a037dbbd39301ab git | Not specified |
| CNA | Linux | Linux | affected 22dd70eb2c3d754862964377a75abafd3167346b f1816b3d7ce80dcf086bb68ff5ae6e09520ca1fa git | Not specified |
| CNA | Linux | Linux | affected 22dd70eb2c3d754862964377a75abafd3167346b fc62a26493a98a0424d9dae2eb92a1daa1321f65 git | Not specified |
| CNA | Linux | Linux | affected 22dd70eb2c3d754862964377a75abafd3167346b 94fd4debd2e3a69cf93e766c8b328a810c228119 git | Not specified |
| CNA | Linux | Linux | affected ae3f9e1221b31b18dbd4c4b85d08574996bbd973 git | Not specified |
| CNA | Linux | Linux | affected ba0db4638525b8b054b3d546b45f7e473f477027 git | Not specified |
| CNA | Linux | Linux | affected 022d81a709cd553bbe2db8675f8e824f4aee6284 git | Not specified |
| CNA | Linux | Linux | affected 16dc252e7007547a7b72a2c21022ef81fb45e6a3 git | Not specified |
| CNA | Linux | Linux | affected 5.15.157 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.88 6.2 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.29 6.7 semver | Not specified |
| CNA | Linux | Linux | affected 6.8.8 6.9 semver | Not specified |
| CNA | Linux | Linux | affected 6.9 | Not specified |
| CNA | Linux | Linux | unaffected 6.9 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/0630bfc773d85ac44da05b2c5a037dbbd39301ab | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/f1816b3d7ce80dcf086bb68ff5ae6e09520ca1fa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/94fd4debd2e3a69cf93e766c8b328a810c228119 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fc62a26493a98a0424d9dae2eb92a1daa1321f65 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.