7.8
CVE-2026-64575
- EPSS 0.12%
- Veröffentlicht 05.08.2026 08:09:31
- Zuletzt bearbeitet 19.08.2026 17:20:17
- CVE-Watchlists
- Unerledigt
bpf: tcp: fix double sock release on batch realloc
In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock. Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release. BUG: KASAN: null-ptr-deref in __sock_gen_cookie Read of size 8 at addr 0000000000000059 by task exploit ... __sock_gen_cookie (net/core/sock_diag.c:28) bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918) bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270) bpf_seq_read (kernel/bpf/bpf_iter.c:205) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 entry_SYSCALL_64_after_hwframe Kernel panic - not syncing: Fatal exception
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9794ac757a650dd594391192183c9caf939f8223
Version <
c842882e4c5d2818b858d6baf3fd10958c93f729
Status
affected
Version
1d7a82c1df5fc397eaca9c6b8c8f61aae9866ad4
Version <
7a6a6d2a127866935f87b55b557bc89693065462
Status
affected
Version
36f955807ee4ede07e9410772f792e4cb4ec807b
Version <
f0c1810320b0dac228103fad7311e89532134d83
Status
affected
Version
cdec67a489d4fdae3e83e04fca0419136a83c4c2
Version <
9f27c4f0ae35b5390ce4f7a54d3501144e41a54d
Status
affected
Version
cdec67a489d4fdae3e83e04fca0419136a83c4c2
Version <
8a726e9585ffe7bfbfad2b5279277a00973970f3
Status
affected
Version
cdec67a489d4fdae3e83e04fca0419136a83c4c2
Version <
980a813452754f8001704744e92f7aa697c53dd3
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.17
Status
affected
Version
0
Version <
6.17
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.022 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/9f27c4f0ae35b5390ce4f7a54d3501144e41a54d
https://git.kernel.org/stable/c/8a726e9585ffe7bfbfad2b5279277a00973970f3
https://git.kernel.org/stable/c/980a813452754f8001704744e92f7aa697c53dd3
https://git.kernel.org/stable/c/7a6a6d2a127866935f87b55b557bc89693065462
https://git.kernel.org/stable/c/c842882e4c5d2818b858d6baf3fd10958c93f729
https://git.kernel.org/stable/c/f0c1810320b0dac228103fad7311e89532134d83