CVE-2026-31673
In the Linux kernel, the following vulnerability has been resolved:
af_unix: read UNIX_DIAG_VFS data under unix_state_l
In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_lock Exact UNIX diag lookups hold a reference to the socket, but not to u-path. Meanwhile, unix_release_sock() clears u-path under unix_state_lock() and drops the path reference after unlocking. Read the inode and device numbers for UNIX_DIAG_VFS while holding unix_state_lock(), then emit the netlink attribute after dropping the lock.
This keeps the VFS data stable while the reply is being built.
HIGH · CVSS 7.8
EPSS 0.00015
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0