CVE-2026-68284 PUBLISHED

bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()

tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork.

This comparison is unsafe when two threads send on the same socket:

Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx)

The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported:

BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0

msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 604326b41a6fb9b4a78b6179335decee0365cd8c to ee762f684eefa59de34d9ed93cab08336e834f47 (excl.)
  • affected from 604326b41a6fb9b4a78b6179335decee0365cd8c to cde4d6bcd9b73073c66498f6723c7b364c4dbc18 (excl.)
  • affected from 604326b41a6fb9b4a78b6179335decee0365cd8c to 786d690257ec7a0c839f8710456e444ce3f1348b (excl.)
  • affected from 604326b41a6fb9b4a78b6179335decee0365cd8c to 752b1159ed5d0c48fe169a3721b96660a9822aa1 (excl.)
  • affected from 604326b41a6fb9b4a78b6179335decee0365cd8c to 2d66a033864e27ab8d5e44cb36f31d9d2413bee4 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.20 is affected
  • unaffected from 0 to 4.20 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References