Answer in brief
CVE-2024-26923 records a Unknown severity vulnerability in af_unix: Fix garbage collector racing against connect(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/RUGGEDCOM RST2428P (generic), Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 family (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <a36ae0ec2353015f0f6762e59f4c2dbc0c906423 || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <343c5372d5e17b306db5f8f3c895539b06e3177f || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <2e2a03787f4f0abc0072350654ab0ef3324d9db3 || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <e76c2678228f6aec74b305ae30c9374cc2f28a51 || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <b75722be422c276b699200de90527d01c602ea7c || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <507cc232ffe53a352847893f8177d276c3b532a9 || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <dbdf7bec5c920200077d693193f989cb1513f009 || >=1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 <47d8ac011fe1c9251070e1bd64cb10b48193ec51 | a36ae0ec2353015f0f6762e59f4c2dbc0c906423, 343c5372d5e17b306db5f8f3c895539b06e3177f, 2e2a03787f4f0abc0072350654ab0ef3324d9db3, e76c2678228f6aec74b305ae30c9374cc2f28a51, b75722be422c276b699200de90527d01c602ea7c, 507cc232ffe53a352847893f8177d276c3b532a9, dbdf7bec5c920200077d693193f989cb1513f009, 47d8ac011fe1c9251070e1bd64cb10b48193ec51 |
| Linux/Linuxgeneric | 2.6.23 | Not reported |
| Siemens/RUGGEDCOM RST2428Pgeneric | >=0 <V3.1 | V3.1 |
| Siemens/SCALANCE XCM-/XRM-/XCH-/XRH-300 familygeneric | >=0 <V3.1 | V3.1 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.0 <V3.1.5 | V3.1.5 |
Published upstream
Apr 24, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embryo has a peer that carries SCM_RIGHTS, two consecutive passes of scan_children() may see a different set of children. Leading to an incorrectly elevated inflight count, and then a dangling pointer within the gc_inflight_list. sockets are AF_UNIX/SOCK_STREAM S is an unconnected socket L is a listening in-flight socket bound to addr, not in fdtable V's fd will be passed via sendmsg(), gets inflight count bumped connect(S, addr) sendmsg(S, [V]); close(V) __unix_gc() ---------------- ------------------------- ----------- NS = unix_create1() skb1 = sock_wmalloc(NS) L = unix_find_other(addr) unix_state_lock(L) unix_peer(S) = NS // V count=1 inflight=0 NS = unix_peer(S) skb2 = sock_alloc() skb_queue_tail(NS, skb2[V]) // V became in-flight // V count=2 inflight=1 close(V) // V count=1 inflight=1 // GC candidate condition met for u in gc_inflight_list: if (total_refs == inflight_refs) add u to gc_candidates // gc_candidates={L, V} for u in gc_candidates: scan_children(u, dec_inflight) // embryo (skb1) was not // reachable from L yet, so V's // inflight remains unchanged __skb_queue_tail(L, skb1) unix_state_unlock(L) for u in gc_candidates: if (u.inflight) scan_children(u, inc_inflight_move_tail) // V count=1 inflight=2 (!) If there is a GC-candidate listening socket, lock/unlock its state. This makes GC wait until the end of any ongoing connect() to that socket. After flipping the lock, a possibly SCM-laden embryo is already enqueued. And if there is another embryo coming, it can not possibly carry SCM_RIGHTS. At this point, unix_inflight() can not happen because unix_gc_lock is already taken. Inflight graph remains unaffected.
Quoted source text, attributed separately from HOL analysis.