Description
In the Linux kernel, the following vulnerability has been resolved:

af_unix: Fix memleak of newsk in unix_stream_connect().

When prepare_peercred() fails in unix_stream_connect(),
unix_release_sock() is not called for newsk, and the memory
is leaked.

Let's move prepare_peercred() before unix_create1().
Published: 2026-05-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel’s af_unix module, a failure in the prepare_peercred() function during a Unix domain socket connection leaves the newly created socket structure (newsk) unreleased. The kernel mistakenly skips the call to unix_release_sock(), resulting in a memory leak. The vulnerability falls under improper resource management (CWE-401). Although the leak does not provide direct code execution, repeated triggering of the failure path can gradually exhaust system memory and degrade availability, which explains the moderate‑severity CVSS score of 5.5.

Affected Systems

The issue affects any Linux kernel build that predates the commit moving prepare_peercred() before unix_create1(). All distributions running a kernel version without the patch are potentially vulnerable. The fix is merged into the mainline kernel and is present in all releases following the commit, so verifying the running kernel version against this change is required.

Risk and Exploitability

The CVSS score of 5.5 shows moderate severity, and the EPSS score of less than 1% indicates the likelihood of exploitation in the wild is low. It is not listed in CISA's KEV catalog. The likely attack vector is inferred: a local attacker who can create or connect to a Unix domain socket could trigger the defective path, and a remote attacker might exploit it if a service exposes Unix sockets externally. Exploitation would require repeated failures in prepare_peercred() to accumulate leaked memory, leading to a denial‑of‑service. No public exploitation has been reported; the risk is largely dependent on how often the vulnerable condition can be exercised.

Generated by OpenCVE AI on August 14, 2026 at 02:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the af_unix memory‑leak fix
  • Restrict or isolate services that create or accept Unix domain sockets to minimize exposure to the failure path
  • Monitor system memory usage for abnormal growth or patterns indicating socket‑related leaks, and configure alerts or automated restarts to respond to sustained exhaustion

Generated by OpenCVE AI on August 14, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 28 May 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Wed, 27 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 27 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix memleak of newsk in unix_stream_connect(). When prepare_peercred() fails in unix_stream_connect(), unix_release_sock() is not called for newsk, and the memory is leaked. Let's move prepare_peercred() before unix_create1().
Title af_unix: Fix memleak of newsk in unix_stream_connect().
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-27T12:16:58.720Z

Reserved: 2026-05-13T15:03:33.082Z

Link: CVE-2026-45887

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T14:17:02.713

Modified: 2026-06-25T21:13:24.180

Link: CVE-2026-45887

cve-icon Redhat

Severity : Low

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-45887 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T03:00:04Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-772

    Missing Release of Resource after Effective Lifetime