CVE-2026-74268

Summary

In the Linux kernel, the following vulnerability has been resolved:

tcp: clear sock_ops cb flags before force-closing a child socket

A child socket inherits the listener's bpf_sock_ops_cb_flags via sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() / tcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where inet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs without it.

If BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state() calls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():

WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550 RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799 Call Trace: <IRQ> tcp_done+0xba/0x250 net/ipv4/tcp.c:5095 tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787 tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926 tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164 </IRQ>

The child is freed before it is ever established, so it should run no sock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(), the common point for the IPv4, IPv6 and chtls forced-close paths and for the MPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done() on a child that was never established too.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 5d5389b2c37ca00da61d1407618ebe15abae0c8baffected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 9f30ba9aa0270a18fdd1e6cd426c480c35f7de9daffected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 71e9c53220abd7f5a45aa4d5e5b420d3479f3a4faffected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 9fffa6465851a1910a6e9cb7272787dd615b26b1affected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < fe23d56e9266d58ba5c380f1970118eedeee0b68affected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < ce311bd2e36596f0aa2c92ca86fb3e019ac57eaeaffected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 8874dafc9099bc49c2e5ebba030f85d276421f92affected
LinuxLinuxd44874910a26f3a8f81edf873a2473363f07f660 < 990348e5bb457697c2f1f7f7b65154a3334d9d2baffected
LinuxLinux4.16affected
LinuxLinux0 < 4.16unaffected
LinuxLinux5.10.270 <= 5.10.*unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References