CVE-2026-97985

In the Linux kernel, the following vulnerability has been resolved: af_unix: Update last skb marker in manage_oob(). Fahad Alharbi reported that blocking recv(MSG_PEEK) could hog CPU due to OOB skb. In the following cases, manage_oob() skips OOB skb(s) and returns NULL for the last recv(MSG_PEEK): socketpair(AF_UNIX, SOCK_STREAM, 0, sk); 1) skb -> OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK); 2) skb -> consumed OOB skb -> NULL send(sk[0], "ab", 2, MSG_OOB); recv(sk[1], buf, 1, MSG_OOB); recv(sk[1], buf, 0, MSG_PEEK); 3) consumed OOB skb -> OOB skb -> NULL send(sk[0], "a", 1, MSG_OOB); recv(sk[1], buf, 0, MSG_OOB); send(sk[0], "b", 1, MSG_OOB); recv(sk[1], buf, 1, MSG_PEEK); Then, @copied is 0 in unix_stream_read_generic() (zero-length buffer, or non-OOB skb is not yet consumed), and unix_stream_data_wait() is called. However, it returns immediately because @last is not updated in unix_stream_read_generic(), and the thread busy-waits for a new skb. Let's update @last in manage_oob(). For MSG_PEEK, @last is updated with the skipped OOB, and for the non-peek case, @last matches the returned value (when !copied) because OOB is unlinked. Note that manage_oob() is inlined and no stack canary is added.

Package Linux Kernel
Published 2026-09-25
Last modified 2026-09-25
Patch available
Yes

Affected versions

Linux kernel versions 5.15.157, 6.1.88, 6.6.29, 6.8.8, 6.9 and later are affected. Fixed in 6.12.111, 6.18.53, 7.2.7, 7.3-rc3 and their respective stable series.

Affected from
≥ 5.15.157 ≥ 6.1.88 ≥ 6.6.29 ≥ 6.8.8 ≥ 6.9
Fixed in
✓ 6.12.111 6.12.x ✓ 6.18.53 6.18.x ✓ 7.2.7 7.2.x ✓ 7.3-rc3

Frequently asked questions

  • What is CVE-2026-97985?

    CVE-2026-97985 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.157 onward and has been patched in 6.12.111, 6.18.53, 7.2.7 and others. CVE-2026-97985 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97985?

    Yes. CVE-2026-97985 has been patched. Fixed versions include 6.12.111, 6.18.53, 7.2.7 and others. If you are running Linux kernel 5.15.157 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97985 actively exploited?

    No. CVE-2026-97985 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.