CVE-2026-74268 PUBLISHED

tcp: clear sock_ops cb flags before force-closing a child socket

Assigner: Linux
Reserved: 15.08.2026 Published: 15.08.2026 Updated: 17.08.2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: clear sock_ops cb flags before force-closing a child socket

A child socket inherits the listener's bpf_sock_ops_cb_flags via sk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() / tcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where inet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs without it.

If BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state() calls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():

WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550 RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799 Call Trace: <IRQ> tcp_done+0xba/0x250 net/ipv4/tcp.c:5095 tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787 tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926 tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164 </IRQ>

The child is freed before it is ever established, so it should run no sock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(), the common point for the IPv4, IPv6 and chtls forced-close paths and for the MPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done() on a child that was never established too.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

AV:N - Remote attackers reach inet_csk_prepare_for_forced_close() via the standard TCP input path (tcp_v4_rcv/tcp_v6_rcv → tcp_check_req → tcp_v4/v6_syn_recv_sock put_and_exit) while processing attacker-sent handshake packets in softirq, with no local access required. AC:L - Attackers control handshake completion and can repeatedly force child setup failures—e.g., MPTCP JOIN/sport-mismatch dispose_child paths, ENOMEM under connection pressure in __inet_inherit_port or MD5/AO copy, or chtls setup failure—making put_and_exit reachable without conditions outside their influence. PR:N - The receive path is pre-authentication TCP/MPTCP processing; no victim credentials or capabilities are required. Exploitation only needs network reachability to a listener whose admin already attached cgroup BPF sock_ops setting BPF_SOCK_OPS_STATE_CB_FLAG (common on Kubernetes/Cilium/cloud nodes). UI:N - No victim interaction is needed beyond normal exposure of a TCP listener; the attacker triggers the bug entirely by sending network packets that complete then fail child socket creation. S:U - Vulnerability impact stays within the kernel on the host receiving the traffic; it does not cross VM, container runtime, or IOMMU security boundaries and represents standard in-kernel memory/lock safety impact. C:H - Inherited BPF_SOCK_OPS_STATE_CB_FLAG causes tcp_call_bpf() to run on an unlocked, partially torn-down child socket; BPF helpers can read tcp_sock fields without proper locking, enabling unsynchronized kernel memory reads that could disclose sensitive data. I:H - tcp_call_bpf() marks is_locked_tcp_sock while the socket lock was dropped, allowing cgroup BPF sock_ops programs to call bpf_setsockopt and modify tcp_sock/kernel state during forced close, creating plausible memory corruption and control-flow compromise primitives. A:H - sock_owned_by_me() WARN fires on this path and concurrent BPF access during tcp_done()/inet_csk_destroy_sock() can cause kernel oops or panic; remote attackers can repeatedly trigger the softirq failure path for denial of service on internet-facing BPF-enabled servers.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d44874910a26f3a8f81edf873a2473363f07f660 to ce311bd2e36596f0aa2c92ca86fb3e019ac57eae (excl.)
  • affected from d44874910a26f3a8f81edf873a2473363f07f660 to 8874dafc9099bc49c2e5ebba030f85d276421f92 (excl.)
  • affected from d44874910a26f3a8f81edf873a2473363f07f660 to 990348e5bb457697c2f1f7f7b65154a3334d9d2b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.16 is affected
  • unaffected from 0 to 4.16 (excl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References