THREAT OPS › Threat News › [NVD] CVE-2026-63979 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved:
net/handshake: hand off the pinned file reference to accept_doit
handshake_req_next() removes the request from the per-net
pending list and drops hn_lock before handshake_nl_accept_doit()
reads req->hr_sk->sk_s
[NVD] CVE-2026-63979 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_s
CVE-2026-63979 CVSS: 9.8 CRITICAL Published: 2026-07-19T16:17:17.070
In the Linux kernel, the following vulnerability has been resolved:
net/handshake: hand off the pinned file reference to accept_doit
handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_socket and dereferences sock->file (once in FD_PREP
Indicators of compromise
- CVE-2026-63979cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63979