CVE-2024-26923 is a race condition in the Linux kernel's AF_UNIX socket garbage collector that occurs when garbage collection runs concurrently with connect() on a partially initialized socket carrying SCM_RIGHTS file descriptors. The race can incorrectly increase an in-flight reference count, leave a dangling pointer in gc_inflight_list, and cause inaccurate active-socket accounting, allowing local resource exhaustion and denial of service. The affected code is net/unix/garbage.c, and the issue has existed since Linux kernel 2.6.23.
Exploitation requires local low-privileged access and difficult-to-reproduce timing conditions, but Red Hat assigns a Moderate severity rating with CVSS 7.0. Fixed upstream kernels include 5.15.156, 6.1.87, 6.6.28, 6.8.7, and 6.9-rc4; Red Hat has issued corrected kernel packages for multiple RHEL 8 and RHEL 9 streams. Organizations should deploy current vendor kernel updates rather than cherry-picking patches; no separate mitigation is known.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:7000 and RHSA-2024:7001 for RHEL 8 kernel and kernel-rt packages, and RHSA-2024:6993 for RHEL 8.8 Extended Update Support kernel packages.
Red Hat issued RHSA-2024:4823 and RHSA-2024:4831, providing fixed kernel and kernel-rt packages for Red Hat Enterprise Linux 9.2 Extended Update Support.
Red Hat released RHSA-2024:8617 with fixed Red Hat Enterprise Linux 9 kernel packages for CVE-2024-26923.
RHSA-2024:7486 provided fixed RHEL 8 kernel packages for Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Fixes were made available in Linux kernel versions 5.15.156, 6.1.87, 6.6.28, 6.8.7, and 6.9-rc4. The fix synchronizes the listening socket state so garbage collection cannot observe an inconsistent SCM_RIGHTS-bearing socket graph during connect().
The Linux kernel CVE team assigned CVE-2024-26923 to a race between AF_UNIX socket garbage collection and connect() processing. The flaw, introduced in Linux kernel 2.6.23, can leave an incorrect in-flight reference count and a dangling pointer in gc_inflight_list.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.