CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of AF_IUCV sockets, where a reference to the socket is not maintained during asynchronous callback execution. This oversight can lead to dereferencing freed memory, potentially causing system crashes or undefined behavior. Organizations using Linux systems that rely on AF_IUCV sockets should prioritize addressing this vulnerability to mitigate risks associated with concurrent socket closures.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock, drops the lock, and then passes the socket to the afiucv_hs_callback_*() handlers without holding a reference. AF_IUCV sockets are not RCU-protected and are freed synchronously by iucv_sock_kill() -> sock_put(), so a concurrent close can free the socket in the window between read_unlock() and the handler, which then dereferences freed memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()). Take a reference with sock_hold() while the socket is still on the list and release it with sock_put() once the handler has run.