PT-2026-51723 · Linux+1 · Linux Kernel+1

CVE-2026-52930

·

Published

2026-06-03

·

Updated

2026-09-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ipc/shm component where the shm destroy orphaned() function iterates through the shm idr using shm ids(ns).rwsem, which fails to serialize all fields evaluated by shm may destroy(). Specifically, the shm nattch variable is updated while holding shm perm.lock, and attach paths can perform this update without holding the rwsem. This creates a race condition where an orphaned segment might be incorrectly identified as unused before the object lock is acquired.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Time Of Check To Time Of Use

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90429
BDU:2026-13906
CVE-2026-52930
ECHO-049F-A2B6-F5C3
OESA-2026-3454
OESA-2026-3455
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3594-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu