CVE-2026-64004
Published Jul 19, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix locking in .getsockopt Mirror iucv_sock_setsockopt() and wrap the whole switch in lock_sock()/release_sock(). The pre-existing SO_MSGLIMIT-only lock becomes redundant and is removed. Any AF_IUCV HIPER user can potentially crash the kernel by racing recvmsg() with getsockopt(SO_MSGSIZE): the SO_MSGSIZE arm dereferences iucv->hs_dev->mtu after iucv_sock_close() (called from the racing recvmsg()) has set hs_dev to NULL, producing a NULL pointer dereference oops.
Is your site exposed to CVE-2026-64004?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1fc30bd4e55e2dd622d2d366cecd732c1841bbee
https://git.kernel.org/stable/c/3589d20a666caf30ad100c960a2de7de390fce88
https://git.kernel.org/stable/c/45bb8de8c95d8899f4b8f61bd9bceb8132af73cb
https://git.kernel.org/stable/c/69554adc7a6fa04ede3ad7512321d83748e3c920
https://git.kernel.org/stable/c/6e792b8dd3002bbc4136745928a9605df1a72b8a
https://git.kernel.org/stable/c/884eb247b74d86db97e3a37f0d6fc8e1e83590dd
https://git.kernel.org/stable/c/9817369243380e287ebe5525411557eaa3aa2a79
https://git.kernel.org/stable/c/cd691beafea0dd779e69e81ccc26b0ab50efcb5e
Frequently Asked Questions
What is CVE-2026-64004? +
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix locking in .getsockopt
Mirror iucv_sock_setsockopt() and wrap the whole switch in
lock_sock()/release_sock(). The pre-existing SO_MSGLIMIT-only lock
becomes redundant and is removed.
Any AF_IUCV HIPER user can potentially crash the kernel by racing
recvmsg() with getsockopt(SO_MSGSIZE): the SO_MSGSIZE arm dereferences
iucv->hs_dev->mtu after iucv_sock_close() (called from the racing
recvmsg()) has set hs_dev to NULL, producing a NULL pointer dereference
oops.
How do I check if I'm vulnerable to CVE-2026-64004? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.