THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63979 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_s

[NVD] CVE-2026-63979 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_s

mednvdPublished 2026-07-19

CVE-2026-63979 CVSS: 9.8 CRITICAL Published: 2026-07-19T16:17:17.070

In the Linux kernel, the following vulnerability has been resolved:

net/handshake: hand off the pinned file reference to accept_doit

handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_socket and dereferences sock->file (once in FD_PREP

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63979