{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-81003","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.812Z","datePublished":"2026-09-11T19:42:56.172Z","dateUpdated":"2026-09-14T11:59:38.541Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:38.541Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: filter frames in afiucv_hs_rcv() by ingress device\n\nafiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte\nname fields in the transport header alone. No check is made against the\nnet_device the frame arrived on.\n\nThis can cause a frame arriving on any netdev to be delivered to an AF_IUCV\nsocket. Three problems follow.\n\nFirst, a frame arriving over HiperSockets can be delivered to a socket\nbound to the classic z/VM IUCV transport, which has iucv->hs_dev == NULL.\niucv_sock_bind() takes the classic path whenever the requested userid\nmatches iucv_userid, even on a guest that also has a HiperSockets device\ncarrying the same identifier. The child socket created by\nafiucv_hs_callback_syn() for such a match inherits hs_dev = NULL and\ntransport = AF_IUCV_TRANS_HIPER, so the first send() on it returns -ENODEV.\nThe socket delivered to accept() is unusable.\n\nSecond, a frame arriving on one netdev can be delivered to a socket bound\nto a different IQD device. Which can lead to\n- Accept-queue exhaustion (DoS)\n- Attacker-controlled peer identity in the child socket\n- Data injection into existing sockets\n- Fabric noise on the IQD fabric, where bogus replies are sent\n- killing established connections\n\nThird, all AF_IUCV sockets live in init_net, as iucv_sock_alloc() calls\nsk_alloc(&init_net, ...). But even frames arriving on netdev devices in a\nnamespace can be delivered to an IUCV socket. So a process in an\nunprivileged user and network namespace holding only the CAP_NET_RAW\ncapability valid within that namespace can send a raw ETH_P_AF_IUCV frame\non its own lo device and have it matched against init_net sockets.\n\nFix all three by skipping any socket whose hs_dev does not match the\ningress device. A classic z/VM IUCV socket has hs_dev == NULL; the ingress\ndev is never NULL, so classic sockets are skipped automatically. An unbound\nHIPER socket also has hs_dev == NULL and is skipped. A bound HIPER socket\nis only reachable from the exact IQD device it was bound to. Because hs_dev\nis always a device in init_net (iucv_sock_bind() scans\nfor_each_netdev_rcu(&init_net, ...) exclusively), a frame whose ingress\ndevice belongs to another namespace never matches any socket.\n\nNote that AF_IUCV over HiperSockets provides no per-connection\nauthentication: no sequence numbers, no TLS, no nonce. The four name fields\nidentifying a connection are exchanged in plaintext on the shared\nHiperSockets segment (VCHID). Any host on the same HiperSockets segment\ncould spoof any frame type against an existing connection. That is a\nprotocol-level property unchanged by this patch. The fix reduces the attack\nsurface to peers present on the same HiperSockets segment."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - afiucv_hs_rcv() is registered via dev_add_pack() for ethertype ETH_P_AF_IUCV (0xFBFB) on every netdevice and matches sockets by name fields only, so crafted L2 frames from a peer LPAR/guest on the HiperSockets VCHID or a host on an attached Ethernet segment reach AF_IUCV sockets; these frames are not IP-routable.\nAC:L - The attacker fully controls the ETH_P_AF_IUCV frames and can set the plaintext dest/src name fields to match a listening or connected socket (names are exchanged in the clear on the fabric and IBM apps use well-known 8-byte names), so matching and delivery are reliable with no race.\nPR:N - afiucv_hs_rcv() runs from netif RX softirq with no authentication, capability, or credential check on the path, so an adjacent HiperSockets or Ethernet peer needs no account or privilege on the victim s390 system.\nUI:N - Exploitation requires only sending crafted frames; the packet handler runs unconditionally in softirq and needs no victim action such as opening a file or mounting a filesystem.\nS:U - Impact is unauthorized delivery into the victim kernel's AF_IUCV sockets within the same OS security authority; this is not a KVM/Xen guest-to-host escape or IOMMU/DMA boundary bypass.\nC:N - The flaw injects attacker-supplied frames into socket receive and control paths and does not provide a kernel memory read, out-of-bounds read, or use-after-free disclosure primitive.\nI:H - Because lookup ignores the ingress device, an attacker can inject arbitrary payload into connected AF_IUCV sockets, spoof the accepted peer identity on SYN, and forge FIN/WIN control frames, fully compromising the integrity of AF_IUCV communications.\nA:H - SYN floods exhaust the listen accept queue and forged FIN/SYN|FIN frames tear down established connections, including classic z/VM IUCV sockets wrongly matched from any netdev, causing complete denial of AF_IUCV services."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/iucv/af_iucv.c"],"versions":[{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"639828ad4d374056167391dbaffd13dd5e5e5ddb","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"92e5c281f1caa287bb58292f2687c9e3ff3aa23e","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"712330f8a4293cfd97b0d62b7c7dc01862a16b98","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"0a5af67e7184c6a0e155c317840bd64b37177af4","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"dfac2936b83be00035ae176f8252e1c1e1de9207","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"8e3763f1ccac3fc395f9af2b87114c023ced8a3f","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"a7f0130a091724e69827ab58e74777a88747e892","status":"affected","versionType":"git"},{"version":"3881ac441f642d56503818123446f7298442236b","lessThan":"80230a18c164a4b5bbc048fe2768b219ac17bc5a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/iucv/af_iucv.c"],"versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/639828ad4d374056167391dbaffd13dd5e5e5ddb"},{"url":"https://git.kernel.org/stable/c/92e5c281f1caa287bb58292f2687c9e3ff3aa23e"},{"url":"https://git.kernel.org/stable/c/712330f8a4293cfd97b0d62b7c7dc01862a16b98"},{"url":"https://git.kernel.org/stable/c/0a5af67e7184c6a0e155c317840bd64b37177af4"},{"url":"https://git.kernel.org/stable/c/dfac2936b83be00035ae176f8252e1c1e1de9207"},{"url":"https://git.kernel.org/stable/c/8e3763f1ccac3fc395f9af2b87114c023ced8a3f"},{"url":"https://git.kernel.org/stable/c/a7f0130a091724e69827ab58e74777a88747e892"},{"url":"https://git.kernel.org/stable/c/80230a18c164a4b5bbc048fe2768b219ac17bc5a"}],"title":"net/iucv: filter frames in afiucv_hs_rcv() by ingress device","x_generator":{"engine":"bippy-1.2.0"}}}}