CVE-2026-97985 PUBLISHED

af_unix: Update last skb marker in manage_oob().

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Update last skb marker in manage_oob().

Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog CPU due to OOB skb.

In the following cases, manage_oob() skips OOB skb(s) and returns NULL for the last recv(MSG_PEEK):

socketpair(AF_UNIX, SOCK_STREAM, 0, sk);

1) skb -> OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK);

2) skb -> consumed OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 1, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK);

3) consumed OOB skb -> OOB skb -> NULL send(sk[0], "a", 1, MSG_OOB); recv(sk[1], buf, 0, MSG_OOB); send(sk[0], "b", 1, MSG_OOB); recv(sk[1], buf, 1, MSG_PEEK);

Then, @copied is 0 in unix_stream_read_generic() (zero-length buffer, or non-OOB skb is not yet consumed), and unix_stream_data_wait() is called.

However, it returns immediately because @last is not updated in unix_stream_read_generic(), and the thread busy-waits for a new skb.

Let's update @last in manage_oob().

For MSG_PEEK, @last is updated with the skipped OOB, and for the non-peek case, @last matches the returned value (when !copied) because OOB is unlinked.

Note that manage_oob() is inlined and no stack canary is added.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 22dd70eb2c3d754862964377a75abafd3167346b to 0630bfc773d85ac44da05b2c5a037dbbd39301ab (excl.)
  • affected from 22dd70eb2c3d754862964377a75abafd3167346b to f1816b3d7ce80dcf086bb68ff5ae6e09520ca1fa (excl.)
  • affected from 22dd70eb2c3d754862964377a75abafd3167346b to fc62a26493a98a0424d9dae2eb92a1daa1321f65 (excl.)
  • affected from 22dd70eb2c3d754862964377a75abafd3167346b to 94fd4debd2e3a69cf93e766c8b328a810c228119 (excl.)
  • Version ae3f9e1221b31b18dbd4c4b85d08574996bbd973 is affected
  • Version ba0db4638525b8b054b3d546b45f7e473f477027 is affected
  • Version 022d81a709cd553bbe2db8675f8e824f4aee6284 is affected
  • Version 16dc252e7007547a7b72a2c21022ef81fb45e6a3 is affected
  • affected from 5.15.157 to 5.16 (excl.)
  • affected from 6.1.88 to 6.2 (excl.)
  • affected from 6.6.29 to 6.7 (excl.)
  • affected from 6.8.8 to 6.9 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.9 is affected
  • unaffected from 0 to 6.9 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References