CVE-2026-68284

Summary

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork.

This comparison is unsafe when two threads send on the same socket:

Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx)

The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported:

BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0

msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux604326b41a6fb9b4a78b6179335decee0365cd8c < ee762f684eefa59de34d9ed93cab08336e834f47affected
LinuxLinux604326b41a6fb9b4a78b6179335decee0365cd8c < cde4d6bcd9b73073c66498f6723c7b364c4dbc18affected
LinuxLinux604326b41a6fb9b4a78b6179335decee0365cd8c < 786d690257ec7a0c839f8710456e444ce3f1348baffected
LinuxLinux604326b41a6fb9b4a78b6179335decee0365cd8c < 752b1159ed5d0c48fe169a3721b96660a9822aa1affected
LinuxLinux604326b41a6fb9b4a78b6179335decee0365cd8c < 2d66a033864e27ab8d5e44cb36f31d9d2413bee4affected
LinuxLinux4.20affected
LinuxLinux0 < 4.20unaffected
LinuxLinux6.6.148 <= 6.6.*unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References