{"api_version":"1","generated_at":"2026-07-20T14:43:33+00:00","cve":"CVE-2026-64177","urls":{"html":"https://cve.report/CVE-2026-64177","api":"https://cve.report/api/cve/CVE-2026-64177.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64177","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64177"},"summary":{"title":"phonet/pep: disable BH around forwarded sk_receive_skb()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: disable BH around forwarded sk_receive_skb()\n\nThe networking receive path is usually run from softirq context, but\nprotocols that take the socket lock may have packets stored in the\nbacklog and processed later from process context. In that case\nrelease_sock() -> __release_sock() drops the slock with spin_unlock_bh()\nand then calls sk->sk_backlog_rcv() with bottom halves enabled.\n\nTypical sk_backlog_rcv handlers process the socket whose backlog is\nbeing drained, so the BH state at entry is irrelevant for the slocks\nthey touch. pep_do_rcv() is different: when the inbound skb targets an\nexisting PEP pipe, it forwards the skb to a different *child* socket\nvia sk_receive_skb(). That helper takes the child slock with\nbh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH\nis already off. The same child slock therefore ends up acquired with\nBH on (process path) and with BH off (softirq path):\n\n  process context                   softirq context\n  ---------------                   ---------------\n  release_sock(listener)            __netif_receive_skb()\n   __release_sock()                  phonet_rcv()\n    spin_unlock_bh()                  __sk_receive_skb(listener)\n    [BH now ENABLED]                  [BH already disabled]\n    sk_backlog_rcv:                   sk_backlog_rcv:\n     pep_do_rcv()                      pep_do_rcv()\n      sk_receive_skb(child)             sk_receive_skb(child)\n       bh_lock_sock_nested(child)        bh_lock_sock_nested(child)\n       => SOFTIRQ-ON-W                   => IN-SOFTIRQ-W\n\nLockdep flags this as inconsistent lock state, and it can become a real\nself-deadlock if a softirq on the same CPU tries to receive to the same\nchild socket while its slock is held in the BH-enabled path:\n\n  WARNING: inconsistent lock state\n  inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n   (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900\n    __sk_receive_skb              net/core/sock.c:563\n    sk_receive_skb                include/net/sock.h:2022 [inline]\n    pep_do_rcv                    net/phonet/pep.c:675\n    sk_backlog_rcv                include/net/sock.h:1190\n    __release_sock                net/core/sock.c:3216\n    release_sock                  net/core/sock.c:3815\n    pep_sock_accept               net/phonet/pep.c:879\n\nWrap the forwarded sk_receive_skb() in local_bh_disable() /\nlocal_bh_enable() so the child slock is always acquired with BH off.\nlocal_bh_disable() nests safely on the softirq path.\n\nDiscovered via in-house syzkaller fuzzing; the same root cause also\non the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c.\nReproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer:\nhttps://pastebin.com/A3t8xzCR","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:59","updated_at":"2026-07-19 16:17:59"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c","name":"https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53","name":"https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e","name":"https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3","name":"https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212","name":"https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b","name":"https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37","name":"https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b","name":"https://git.kernel.org/stable/c/f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64177","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64177","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 b2606c302d7f2b4ee48da05e32ed60aed1b0cd53 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 02c04df84de709060f63e1d52ec67488c4f6f212 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 8420aa4900417797323dd567ba9d1512280c2dc3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 bd795f106b3889fb0706c6e4831c4b27e2b5666b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 84bc87beb4cd77670939b446326788e4c9b3db37 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 a3fc8f2dacd1c37325977fc1fbbf3d52141df99e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9641458d3ec42def729fde64669abf07f3220cd5 dbc81608e3a653dea6cf403f20cae35468b8ab9c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.28","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.28 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.258 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.209 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.175 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.142 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.92 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/phonet/pep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"b2606c302d7f2b4ee48da05e32ed60aed1b0cd53","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"02c04df84de709060f63e1d52ec67488c4f6f212","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"8420aa4900417797323dd567ba9d1512280c2dc3","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"bd795f106b3889fb0706c6e4831c4b27e2b5666b","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"84bc87beb4cd77670939b446326788e4c9b3db37","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"a3fc8f2dacd1c37325977fc1fbbf3d52141df99e","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"},{"lessThan":"dbc81608e3a653dea6cf403f20cae35468b8ab9c","status":"affected","version":"9641458d3ec42def729fde64669abf07f3220cd5","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/phonet/pep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.28"},{"lessThan":"2.6.28","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.258","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.258","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.209","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.175","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.142","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.92","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"2.6.28","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"2.6.28","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: disable BH around forwarded sk_receive_skb()\n\nThe networking receive path is usually run from softirq context, but\nprotocols that take the socket lock may have packets stored in the\nbacklog and processed later from process context. In that case\nrelease_sock() -> __release_sock() drops the slock with spin_unlock_bh()\nand then calls sk->sk_backlog_rcv() with bottom halves enabled.\n\nTypical sk_backlog_rcv handlers process the socket whose backlog is\nbeing drained, so the BH state at entry is irrelevant for the slocks\nthey touch. pep_do_rcv() is different: when the inbound skb targets an\nexisting PEP pipe, it forwards the skb to a different *child* socket\nvia sk_receive_skb(). That helper takes the child slock with\nbh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH\nis already off. The same child slock therefore ends up acquired with\nBH on (process path) and with BH off (softirq path):\n\n  process context                   softirq context\n  ---------------                   ---------------\n  release_sock(listener)            __netif_receive_skb()\n   __release_sock()                  phonet_rcv()\n    spin_unlock_bh()                  __sk_receive_skb(listener)\n    [BH now ENABLED]                  [BH already disabled]\n    sk_backlog_rcv:                   sk_backlog_rcv:\n     pep_do_rcv()                      pep_do_rcv()\n      sk_receive_skb(child)             sk_receive_skb(child)\n       bh_lock_sock_nested(child)        bh_lock_sock_nested(child)\n       => SOFTIRQ-ON-W                   => IN-SOFTIRQ-W\n\nLockdep flags this as inconsistent lock state, and it can become a real\nself-deadlock if a softirq on the same CPU tries to receive to the same\nchild socket while its slock is held in the BH-enabled path:\n\n  WARNING: inconsistent lock state\n  inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n   (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900\n    __sk_receive_skb              net/core/sock.c:563\n    sk_receive_skb                include/net/sock.h:2022 [inline]\n    pep_do_rcv                    net/phonet/pep.c:675\n    sk_backlog_rcv                include/net/sock.h:1190\n    __release_sock                net/core/sock.c:3216\n    release_sock                  net/core/sock.c:3815\n    pep_sock_accept               net/phonet/pep.c:879\n\nWrap the forwarded sk_receive_skb() in local_bh_disable() /\nlocal_bh_enable() so the child slock is always acquired with BH off.\nlocal_bh_disable() nests safely on the softirq path.\n\nDiscovered via in-house syzkaller fuzzing; the same root cause also\non the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c.\nReproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer:\nhttps://pastebin.com/A3t8xzCR"}],"providerMetadata":{"dateUpdated":"2026-07-19T15:41:01.534Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/f08c45076e4fd8b0adbc5eb186d6e6a3e7350d7b"},{"url":"https://git.kernel.org/stable/c/b2606c302d7f2b4ee48da05e32ed60aed1b0cd53"},{"url":"https://git.kernel.org/stable/c/02c04df84de709060f63e1d52ec67488c4f6f212"},{"url":"https://git.kernel.org/stable/c/8420aa4900417797323dd567ba9d1512280c2dc3"},{"url":"https://git.kernel.org/stable/c/bd795f106b3889fb0706c6e4831c4b27e2b5666b"},{"url":"https://git.kernel.org/stable/c/84bc87beb4cd77670939b446326788e4c9b3db37"},{"url":"https://git.kernel.org/stable/c/a3fc8f2dacd1c37325977fc1fbbf3d52141df99e"},{"url":"https://git.kernel.org/stable/c/dbc81608e3a653dea6cf403f20cae35468b8ab9c"}],"title":"phonet/pep: disable BH around forwarded sk_receive_skb()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64177","datePublished":"2026-07-19T15:41:01.534Z","dateReserved":"2026-07-19T07:54:57.039Z","dateUpdated":"2026-07-19T15:41:01.534Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:59","lastModifiedDate":"2026-07-19 16:17:59","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64177","Ordinal":"1","Title":"phonet/pep: disable BH around forwarded sk_receive_skb()","CVE":"CVE-2026-64177","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64177","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: disable BH around forwarded sk_receive_skb()\n\nThe networking receive path is usually run from softirq context, but\nprotocols that take the socket lock may have packets stored in the\nbacklog and processed later from process context. In that case\nrelease_sock() -> __release_sock() drops the slock with spin_unlock_bh()\nand then calls sk->sk_backlog_rcv() with bottom halves enabled.\n\nTypical sk_backlog_rcv handlers process the socket whose backlog is\nbeing drained, so the BH state at entry is irrelevant for the slocks\nthey touch. pep_do_rcv() is different: when the inbound skb targets an\nexisting PEP pipe, it forwards the skb to a different *child* socket\nvia sk_receive_skb(). That helper takes the child slock with\nbh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH\nis already off. The same child slock therefore ends up acquired with\nBH on (process path) and with BH off (softirq path):\n\n  process context                   softirq context\n  ---------------                   ---------------\n  release_sock(listener)            __netif_receive_skb()\n   __release_sock()                  phonet_rcv()\n    spin_unlock_bh()                  __sk_receive_skb(listener)\n    [BH now ENABLED]                  [BH already disabled]\n    sk_backlog_rcv:                   sk_backlog_rcv:\n     pep_do_rcv()                      pep_do_rcv()\n      sk_receive_skb(child)             sk_receive_skb(child)\n       bh_lock_sock_nested(child)        bh_lock_sock_nested(child)\n       => SOFTIRQ-ON-W                   => IN-SOFTIRQ-W\n\nLockdep flags this as inconsistent lock state, and it can become a real\nself-deadlock if a softirq on the same CPU tries to receive to the same\nchild socket while its slock is held in the BH-enabled path:\n\n  WARNING: inconsistent lock state\n  inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n   (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900\n    __sk_receive_skb              net/core/sock.c:563\n    sk_receive_skb                include/net/sock.h:2022 [inline]\n    pep_do_rcv                    net/phonet/pep.c:675\n    sk_backlog_rcv                include/net/sock.h:1190\n    __release_sock                net/core/sock.c:3216\n    release_sock                  net/core/sock.c:3815\n    pep_sock_accept               net/phonet/pep.c:879\n\nWrap the forwarded sk_receive_skb() in local_bh_disable() /\nlocal_bh_enable() so the child slock is always acquired with BH off.\nlocal_bh_disable() nests safely on the softirq path.\n\nDiscovered via in-house syzkaller fuzzing; the same root cause also\non the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c.\nReproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer:\nhttps://pastebin.com/A3t8xzCR","Type":"Description","Title":"phonet/pep: disable BH around forwarded sk_receive_skb()"}]}}}