From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4D4474A8A36 for ; Fri, 11 Sep 2026 19:49:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156154; cv=none; b=hOmBU4q0Kwk490Y3gXP2lo6LLYTA6kkCHArdkHHz0n7ZADpHcZioAw7cZ2T/nyo5PzFciuymWHc6zqezRoqBCPYAkZbZEgK+mZWRqGxurd138a809jcEjniT8SMTuXO/IQh/ejWcy19UmAGrHxIBsW9NTKA1T6FF8QsXA0rOH40= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156154; c=relaxed/simple; bh=IhL1uyEcUUeKODzzrSqjEjLPgpooz0mz7mc5b0wlc7g=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=tSs/3uHNCTB1mY5pgiITO+2bdAlvsBMNPDblrLg0NbVT+hQjnAnNyCGLOhNkVQ0O1tB2lZ6Vu+u3M69vpCQixLzbmjg6imt1ZGdtaGiJc49bc8rDiOD/BUfz0u8ya/CyPeMIazkjoWn5FTLF4K5oLxHq2afxkWncBD23ILfwr50= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=nRawmME0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="nRawmME0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D51451F0089A; Fri, 11 Sep 2026 19:49:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156145; bh=efnx5CpCFxnEUEHF4mP1o5yNvrFvGBQhpsBBwjB8KCY=; h=From:To:Cc:Subject:Date:Reply-To; b=nRawmME0yIoTYZoHruFyidExCHd4+2e0uSbemhl8PVVE5TCI+sAR+egTWy1SdDYqw dhEmqyx/f+HZy458M+yjptYj2mivT3VGy3bCgGKVXB3kZ6AqI2IV0953hm+ZUvC/wm Vdb43igPbskM9Yn/os/RwkDSkyVK3zvewPVg6GNY= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-81003: net/iucv: filter frames in afiucv_hs_rcv() by ingress device Date: Fri, 11 Sep 2026 21:41:49 +0200 Message-ID: <2026091151-CVE-2026-81003-4d0a@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4898; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=iP6hCu3LbXeab2D+EzvHMDJNQyGcoGgRqk4VDnjBDug=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIp0d72z4MKtUvqb86YpJ0RV2/lKtZTwlesW33m3bb /AtcsX0jlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIhBMM8+P/bw5h+NvfxP3/ rtQDAX9uAQaNP0DRBXEX7/wO/1rNcMR6ptLK+swrnBoA X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport header alone. No check is made against the net_device the frame arrived on. This can cause a frame arriving on any netdev to be delivered to an AF_IUCV socket. Three problems follow. First, a frame arriving over HiperSockets can be delivered to a socket bound to the classic z/VM IUCV transport, which has iucv->hs_dev == NULL. iucv_sock_bind() takes the classic path whenever the requested userid matches iucv_userid, even on a guest that also has a HiperSockets device carrying the same identifier. The child socket created by afiucv_hs_callback_syn() for such a match inherits hs_dev = NULL and transport = AF_IUCV_TRANS_HIPER, so the first send() on it returns -ENODEV. The socket delivered to accept() is unusable. Second, a frame arriving on one netdev can be delivered to a socket bound to a different IQD device. Which can lead to - Accept-queue exhaustion (DoS) - Attacker-controlled peer identity in the child socket - Data injection into existing sockets - Fabric noise on the IQD fabric, where bogus replies are sent - killing established connections Third, all AF_IUCV sockets live in init_net, as iucv_sock_alloc() calls sk_alloc(&init_net, ...). But even frames arriving on netdev devices in a namespace can be delivered to an IUCV socket. So a process in an unprivileged user and network namespace holding only the CAP_NET_RAW capability valid within that namespace can send a raw ETH_P_AF_IUCV frame on its own lo device and have it matched against init_net sockets. Fix all three by skipping any socket whose hs_dev does not match the ingress device. A classic z/VM IUCV socket has hs_dev == NULL; the ingress dev is never NULL, so classic sockets are skipped automatically. An unbound HIPER socket also has hs_dev == NULL and is skipped. A bound HIPER socket is only reachable from the exact IQD device it was bound to. Because hs_dev is always a device in init_net (iucv_sock_bind() scans for_each_netdev_rcu(&init_net, ...) exclusively), a frame whose ingress device belongs to another namespace never matches any socket. Note that AF_IUCV over HiperSockets provides no per-connection authentication: no sequence numbers, no TLS, no nonce. The four name fields identifying a connection are exchanged in plaintext on the shared HiperSockets segment (VCHID). Any host on the same HiperSockets segment could spoof any frame type against an existing connection. That is a protocol-level property unchanged by this patch. The fix reduces the attack surface to peers present on the same HiperSockets segment. The Linux kernel CVE team has assigned CVE-2026-81003 to this issue. Affected and fixed versions =========================== Issue introduced in 3.2 with commit 3881ac441f642d56503818123446f7298442236b and fixed in 6.12.109 with commit dfac2936b83be00035ae176f8252e1c1e1de9207 Issue introduced in 3.2 with commit 3881ac441f642d56503818123446f7298442236b and fixed in 6.18.50 with commit 8e3763f1ccac3fc395f9af2b87114c023ced8a3f Issue introduced in 3.2 with commit 3881ac441f642d56503818123446f7298442236b and fixed in 7.2.4 with commit a7f0130a091724e69827ab58e74777a88747e892 Issue introduced in 3.2 with commit 3881ac441f642d56503818123446f7298442236b and fixed in 7.3-rc1 with commit 80230a18c164a4b5bbc048fe2768b219ac17bc5a Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-81003 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/iucv/af_iucv.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/dfac2936b83be00035ae176f8252e1c1e1de9207 https://git.kernel.org/stable/c/8e3763f1ccac3fc395f9af2b87114c023ced8a3f https://git.kernel.org/stable/c/a7f0130a091724e69827ab58e74777a88747e892 https://git.kernel.org/stable/c/80230a18c164a4b5bbc048fe2768b219ac17bc5a