HIGH Public exploit
BadGarbage
CVE-2026-53361
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
KernelScan AI7.3HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() `- if (!gc_in_progress) `- if (!gc_in_progress) |- gc_in_progress = true | `- queue_work() | unix_gc() <----------------/ | | |- gc_in_progress = true ... `- queue_work() | | `- gc_in_progress = false | | unix_gc() <---------------------------------------------' | ... /* gc_in_progress == false */ | `- gc_in_progress = false unix_peek_fpl() relies on gc_in_progress not to confuse GC by MSG_PEEK. Let's set gc_in_progress to true in unix_gc().
02KernelScan AI Analysis
Risk summary
A race condition in the AF_UNIX socket garbage collector allows the GC to execute with its progress flag cleared, breaking synchronization with MSG_PEEK operations. This can cause the collector to free objects still in use, leading to use-after-free memory corruption. Any unprivileged local user can trigger this by creating enough inflight AF_UNIX sockets.
Vulnerability analysis
A race condition in the AF_UNIX socket garbage collector allows the collector to run without its active flag set. A concurrent message-peek operation checks this flag to avoid interfering with collection; when the flag is missing, the peek can confuse the collector into freeing socket objects that are still referenced, resulting in use-after-free memory corruption. The fix ensures every garbage-collection run unconditionally marks itself as active before examining any sockets, removing the window where a later-scheduled collection could start with the flag still cleared. Any local user can reach this path by creating many in-flight AF_UNIX sockets and sending messages to trigger the collector; no special privileges or hardware access are required.
Exploit availability
KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.18 | — | 6.18.38 | 0cfa78c05066 |
| 6.12 | — | 6.12.95 | 591f1ac21742 |
| mainline | — | 7.1 | d82ba05263c6 |
| 6.1 | 6.1.141 | 6.1.183 | 20aa894d475b |
| 6.6 | 6.6.93 | 6.6.144 | 82c17e13d404 |