In the Linux kernel, the following vulnerability has been resolved:
tcp: clear sock_ops cb flags before force-closing a child socket
A child socket inherits the listener's bpf_sock_ops_cb_flags via
sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() /
tcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where
inet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs
without it.
If BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state()
calls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():
WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550
RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799
Call Trace:
<IRQ>
tcp_done+0xba/0x250 net/ipv4/tcp.c:5095
tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787
tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926
tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164
</IRQ>
The child is freed before it is ever established, so it should run no
sock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(),
the common point for the IPv4, IPv6 and chtls forced-close paths and for the
MPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done()
on a child that was never established too.
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
AV:N - Remote attackers reach inet_csk_prepare_for_forced_close() via the standard TCP input path (tcp_v4_rcv/tcp_v6_rcv → tcp_check_req → tcp_v4/v6_syn_recv_sock put_and_exit) while processing attacker-sent handshake packets in softirq, with no local access required.
AC:L - Attackers control handshake completion and can repeatedly force child setup failures—e.g., MPTCP JOIN/sport-mismatch dispose_child paths, ENOMEM under connection pressure in __inet_inherit_port or MD5/AO copy, or chtls setup failure—making put_and_exit reachable without conditions outside their influence.
PR:N - The receive path is pre-authentication TCP/MPTCP processing; no victim credentials or capabilities are required. Exploitation only needs network reachability to a listener whose admin already attached cgroup BPF sock_ops setting BPF_SOCK_OPS_STATE_CB_FLAG (common on Kubernetes/Cilium/cloud nodes).
UI:N - No victim interaction is needed beyond normal exposure of a TCP listener; the attacker triggers the bug entirely by sending network packets that complete then fail child socket creation.
S:U - Vulnerability impact stays within the kernel on the host receiving the traffic; it does not cross VM, container runtime, or IOMMU security boundaries and represents standard in-kernel memory/lock safety impact.
C:H - Inherited BPF_SOCK_OPS_STATE_CB_FLAG causes tcp_call_bpf() to run on an unlocked, partially torn-down child socket; BPF helpers can read tcp_sock fields without proper locking, enabling unsynchronized kernel memory reads that could disclose sensitive data.
I:H - tcp_call_bpf() marks is_locked_tcp_sock while the socket lock was dropped, allowing cgroup BPF sock_ops programs to call bpf_setsockopt and modify tcp_sock/kernel state during forced close, creating plausible memory corruption and control-flow compromise primitives.
A:H - sock_owned_by_me() WARN fires on this path and concurrent BPF access during tcp_done()/inet_csk_destroy_sock() can cause kernel oops or panic; remote attackers can repeatedly trigger the softirq failure path for denial of service on internet-facing BPF-enabled servers.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
Low |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - Remote attackers reach inet_csk_prepare_for_forced_close() via the standard TCP input path (tcp_v4_rcv/tcp_v6_rcv → tcp_check_req → tcp_v4/v6_syn_recv_sock put_and_exit) while processing attacker-sent handshake packets in softirq, with no local access required.
AC:L - Attackers control handshake completion and can repeatedly force child setup failures—e.g., MPTCP JOIN/sport-mismatch dispose_child paths, ENOMEM under connection pressure in __inet_inherit_port or MD5/AO copy, or chtls setup failure—making put_and_exit reachable without conditions outside their influence.
PR:N - The receive path is pre-authentication TCP/MPTCP processing; no victim credentials or capabilities are required. Exploitation only needs network reachability to a listener whose admin already attached cgroup BPF sock_ops setting BPF_SOCK_OPS_STATE_CB_FLAG (common on Kubernetes/Cilium/cloud nodes).
UI:N - No victim interaction is needed beyond normal exposure of a TCP listener; the attacker triggers the bug entirely by sending network packets that complete then fail child socket creation.
S:U - Vulnerability impact stays within the kernel on the host receiving the traffic; it does not cross VM, container runtime, or IOMMU security boundaries and represents standard in-kernel memory/lock safety impact.
C:H - Inherited BPF_SOCK_OPS_STATE_CB_FLAG causes tcp_call_bpf() to run on an unlocked, partially torn-down child socket; BPF helpers can read tcp_sock fields without proper locking, enabling unsynchronized kernel memory reads that could disclose sensitive data.
I:H - tcp_call_bpf() marks is_locked_tcp_sock while the socket lock was dropped, allowing cgroup BPF sock_ops programs to call bpf_setsockopt and modify tcp_sock/kernel state during forced close, creating plausible memory corruption and control-flow compromise primitives.
A:H - sock_owned_by_me() WARN fires on this path and concurrent BPF access during tcp_done()/inet_csk_destroy_sock() can cause kernel oops or panic; remote attackers can repeatedly trigger the softirq failure path for denial of service on internet-facing BPF-enabled servers.
CVSS 3.1