CVE-2026-52928 PUBLISHED

af_unix: Reject SIOCATMARK on non-stream sockets

Assigner: Linux
Reserved: 09.06.2026 Published: 24.06.2026 Updated: 24.06.2026

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Reject SIOCATMARK on non-stream sockets

SIOCATMARK reports whether the receive queue is at the urgent mark for MSG_OOB.

In AF_UNIX, MSG_OOB is supported only for SOCK_STREAM sockets. SOCK_DGRAM and SOCK_SEQPACKET reject MSG_OOB in sendmsg() and recvmsg(), so they should not support SIOCATMARK either.

Return -EOPNOTSUPP for non-stream sockets before checking the receive queue.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 314001f0bf927015e459c9d387d62a231fe93af3 to 645b1ed3259af38b7814242a420bc2081bdd1eb6 (excl.)
  • affected from 314001f0bf927015e459c9d387d62a231fe93af3 to c34c41446acf6c0d13b5b06c809be11e0f7f2729 (excl.)
  • affected from 314001f0bf927015e459c9d387d62a231fe93af3 to 3147ddf5a41c20c45c2eb69e00b62f10f822056a (excl.)
  • affected from 314001f0bf927015e459c9d387d62a231fe93af3 to d119775f2bad827edc28071c061fdd4a91f889a5 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.15 is affected
  • unaffected from 0 to 5.15 (excl.)
  • unaffected from 6.12.88 to 6.12.* (incl.)
  • unaffected from 6.18.30 to 6.18.* (incl.)
  • unaffected from 7.0.7 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References