Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-63979

net/handshake: hand off the pinned file reference to accept_doit
Back to all
CVE

CVE-2026-63979

net/handshake: hand off the pinned file reference to accept_doit

In the Linux kernel, the following vulnerability has been resolved:

net/handshake: hand off the pinned file reference to accept_doit

handshakereqnext() removes the request from the per-net

pending list and drops hnlock before handshakenlacceptdoit()

reads req->hrsk->sksocket and dereferences sock->file (once in

FDPREPARE() and again in getfile()).  In that window a

consumer running tlshandshakecancel() followed by sockfd_put()

(svcsockfree) or _fputsync() (xsresettransport) releases

sock->file.  sockrelease() then runs sockorphan(), zeroing

sk_socket, and frees the struct socket.  The accept-side code

either reads NULL through sk_socket or chases freed memory.

The submit-side sockhold() does not prevent this.  skrefcnt

protects struct sock, but struct socket and sock->file are

independently refcounted via the file descriptor the consumer

owns.  Pinning sk leaves sock and sock->file unprotected.

Retarget the accept-side dereferences at req->hr_file, which was

pinned at submit time, instead of req->hrsk->sksocket->file.

Pinning on its own is not sufficient: a consumer that cancels

between handshakereqnext() returning and accept_doit reaching

FDPREPARE() takes the !removepending() branch in

handshakereqcancel() and drops hr_file before the accept side

takes its own reference.  Hand off an additional file reference

inside handshakereqnext(), under hn_lock, so the accept side

operates on a reference that no concurrent handshakereqcancel()

can revoke.  FD_PREPARE() consumes that handed-off reference,

either by transferring it to the new fd in fd_publish() or by

dropping it in the cleanup destructor on error; the explicit

getfile() that previously balanced FDPREPARE() is therefore

redundant and goes away.

Update handshakereqcanceltest2 and test3 to simulate the

FD_PREPARE() consumption with an fput() so the kunit file-count

assertions stay balanced.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/68eba6519cbd6359fb554a9720f3a3b6b2eba23f, https://git.kernel.org/stable/c/c06876d4fac38f35820946ee3b1be7d7da799cd4, https://git.kernel.org/stable/c/f4251190e58b209999c1ba9e6d2976136a1be055, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63979.json, https://nvd.nist.gov/vuln/detail/CVE-2026-63979, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00614%
EPSS Percentile
0.46914%
Introduced Version
3b3009ea8abb713b022d94fba95ec270cf6e7eae,6.4.0,6.19.0,0
Fix Available
f4251190e58b209999c1ba9e6d2976136a1be055,6.18.44,7.0.12,7.0.0-28.28~24.04.1,7.0.0-1016.16~24.04.1,7.0.0-28.28.1~24.04.3

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading