Local denial of service via sleeping socket lock
Published Jun 25, 2026 · Updated Jun 25, 2026
Improper locking in the Linux Kernel net/smc subsystem allows local users to hang kernel workers through a crafted socket option. __smc_setsockopt() copies attacker-controlled optval memory while lock_sock() remains held, so a stalled userfaultfd or FUSE-backed read retains the socket lock indefinitely. Unprivileged local access and concurrent teardown such as shutdown() are required; the held lock exhausts kernel workers and triggers the hung-task watchdog.
Summary
What happened
Improper locking in the Linux Kernel net/smc subsystem allows local users to hang kernel workers through a crafted socket option. __smc_setsockopt() copies attacker-controlled optval memory while lock_sock() remains held, so a stalled userfaultfd or FUSE-backed read retains the socket lock indefinitely. Unprivileged local access and concurrent teardown such as shutdown() are required; the held lock exhausts kernel workers and triggers the hung-task watchdog.
The record
- CVE
- CVE-2026-53274
- Published
- Jun 25, 2026
- Updated
- Jun 25, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux Kernel
- Classifications
- T1499.004
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jun 25, 2026CVE publishedPublication date reported by the CVE source.
- Jun 25, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=5.18
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <35a22117839602bb52283de08894c5a7dde92420
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <5d27d2ffe487df89ce28fda0410eafa05dbe03a0
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <89f6fbe0033c942cb790ffd53ca93a45eeaf1c91
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <94d286fa5eedc550d42bcb9c85416af8f77736ff
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <a3fdd924d88c30b9f488636ce0e4696012cf5511
- Affected versionversion=a6a6fe27bab48f0d09a64b051e7bde432fcae081 <dcd90f42a33e4220385f27b515183d0c91b2fc4a
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo