{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-68140","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-30T09:28:09.370Z","datePublished":"2026-08-10T11:59:03.761Z","dateUpdated":"2026-08-19T16:29:57.127Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:29:57.127Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: fix use-after-free of a severed iucv_path\n\naf_iucv queues not-yet-received message notifications on iucv->message_q,\neach holding a raw pointer to the connection's iucv_path.  When the peer\nsevers the connection, iucv_sever_path() frees that path with\niucv_path_free() but leaves the notifications queued.  A later recvmsg()\ndrains message_q via iucv_process_message_q() and hands the stale path to\nmessage_receive() -- a use-after-free of the freed iucv_path.\n\nDrop the queued notifications when the path is severed; once the path is\ngone they can no longer be received.  This also frees the notifications\nleaked when a socket is closed with messages still queued."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - An adjacent z/VM guest or LPAR peer can establish an AF_IUCV connection and deliver IUCV message_pending and path_severed events to a victim; exploitation requires same-CPC IUCV reachability, not Internet-wide access.\nAC:L - The attacker deterministically floods IUCV messages to fill message_q, severs the connection to free iucv_path, then victim recvmsg() drains the stale queue; no uncontrollable timing or memory-layout luck is required.\nPR:N - On the victim, no local Linux account or capability is needed; any unauthorized adjacent IUCV peer that completes the AF_IUCV handshake can flood messages and sever the path against a listening service.\nUI:N - No special victim action is required beyond normal server recvmsg() on an established IUCV session; the attacker drives connection setup, message flood, and path sever entirely from the peer side.\nS:U - Impact is kernel memory corruption within the victim Linux guest; it does not cross hypervisor, VM-escape, or IOMMU security boundaries.\nC:H - Queued notifications dereference a freed struct iucv_path in message_receive(), passing stale pathid and private fields into CP IUCV RECEIVE calls—a classic UAF enabling attacker-controlled heap reuse and kernel memory disclosure.\nI:H - Use-after-free of iucv_path lets an attacker reclaim the freed object and supply forged pathid and list pointers used by __iucv_message_receive(), providing heap corruption primitives suitable for arbitrary kernel write or code execution.\nA:H - Processing the stale path in iucv_process_message_q() dereferences freed kernel memory during message_receive(), reliably causing kernel oops or panic and total loss of availability even before full exploitation."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/iucv/af_iucv.c"],"versions":[{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"5f08c5e50bcb4680069bd3f9edd5728308816ded","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"c24faf11bd31bfe0500aca12cbdd5a573a954a5d","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"99ddb33748698296a6f17b9b34aa3d16a406bb3c","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"23658b350b4107e8292045c2044983fd426fa15d","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"a5bbaddf69853117f28173c3f5c8fc14c6b2ec82","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"900cd6d8119b7f3ae5c4bf82f922ff5957df43db","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"f579582c03ed526281a8450159baf1d35099a85f","status":"affected","versionType":"git"},{"version":"f0703c80e5156406ad947cb67fe277725b48080f","lessThan":"be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/iucv/af_iucv.c"],"versions":[{"version":"2.6.24","status":"affected"},{"version":"0","lessThan":"2.6.24","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"7.1.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.24","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5f08c5e50bcb4680069bd3f9edd5728308816ded"},{"url":"https://git.kernel.org/stable/c/c24faf11bd31bfe0500aca12cbdd5a573a954a5d"},{"url":"https://git.kernel.org/stable/c/99ddb33748698296a6f17b9b34aa3d16a406bb3c"},{"url":"https://git.kernel.org/stable/c/23658b350b4107e8292045c2044983fd426fa15d"},{"url":"https://git.kernel.org/stable/c/a5bbaddf69853117f28173c3f5c8fc14c6b2ec82"},{"url":"https://git.kernel.org/stable/c/900cd6d8119b7f3ae5c4bf82f922ff5957df43db"},{"url":"https://git.kernel.org/stable/c/f579582c03ed526281a8450159baf1d35099a85f"},{"url":"https://git.kernel.org/stable/c/be7cc4656eb1f54029610e82d1f0fdd3f9b5ec0a"}],"title":"net/iucv: fix use-after-free of a severed iucv_path","x_generator":{"engine":"bippy-1.2.0"}}}}