CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of socket connections, specifically in the `afiucv_hs_callback_syn()` function, where a NULL pointer dereference occurs if socket allocation fails. This can lead to a system crash or denial of service when the code attempts to terminate a non-existent socket. System administrators and developers managing Linux environments should prioritize this issue to prevent potential service disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC. If the allocation fails, nsk is NULL. The connection-refused path is entered when the listen state check fails, the accept backlog is full, or nsk is NULL. The code unconditionally calls iucv_sock_kill(nsk) in that path. iucv_sock_kill() does not accept a NULL socket pointer and immediately dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL, calling iucv_sock_kill(nsk) results in a NULL pointer dereference. Only call iucv_sock_kill() when a child socket was successfully allocated.