7.8

CVE-2026-68284

bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which
drops and reacquires the socket lock.  Its error path tries to decide
whether msg_tx names the local temporary message by comparing it with
the current value of psock->cork.

This comparison is unsafe when two threads send on the same socket:

  Thread A                         Thread B
  msg_tx = psock->cork
  sk_msg_alloc() fails
  sk_stream_wait_memory()
    releases the socket lock      acquires the socket lock
                                  completes the cork
                                  psock->cork = NULL
                                  frees the cork
    reacquires the socket lock
  msg_tx != psock->cork
  sk_msg_free(msg_tx)

The stale cork is therefore mistaken for the local temporary message
and freed again.  KASAN reported:

  BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50
  Read of size 4 at addr ffff88810c908800 by task poc/90
  Call Trace:
   sk_msg_free+0x49/0x50
   tcp_bpf_sendmsg+0x14f5/0x1cc0
   __sys_sendto+0x32c/0x3a0
   __x64_sys_sendto+0xdb/0x1b0
  Allocated by task 89:
   __kasan_kmalloc+0x8f/0xa0
   tcp_bpf_sendmsg+0x16b3/0x1cc0
  Freed by task 91:
   __kasan_slab_free+0x43/0x70
   kfree+0x131/0x3c0
   tcp_bpf_sendmsg+0xec3/0x1cc0

msg_tx can only name the stack-local tmp or the shared cork. Check for
tmp directly so a changed psock->cork cannot turn a shared message into
an apparent local one.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < 0688e6fe599d2d39147ae9ece97944c6e1815ebf
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < b2bcbeabfd843d47468fa095b1bd08ddb90cf616
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < 54be47e7cbb936429c3bbdfc526ea943954aaf80
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < ee762f684eefa59de34d9ed93cab08336e834f47
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < cde4d6bcd9b73073c66498f6723c7b364c4dbc18
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < 786d690257ec7a0c839f8710456e444ce3f1348b
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < 752b1159ed5d0c48fe169a3721b96660a9822aa1
Status affected
Version 604326b41a6fb9b4a78b6179335decee0365cd8c
Version < 2d66a033864e27ab8d5e44cb36f31d9d2413bee4
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.20
Status affected
Version 0
Version < 4.20
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47
https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18
https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b
https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1
https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4
https://git.kernel.org/stable/c/0688e6fe599d2d39147ae9ece97944c6e1815ebf
https://git.kernel.org/stable/c/54be47e7cbb936429c3bbdfc526ea943954aaf80
https://git.kernel.org/stable/c/b2bcbeabfd843d47468fa095b1bd08ddb90cf616