CVE-2026-68284

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2026
Last modified:
17/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()<br /> <br /> tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which<br /> drops and reacquires the socket lock. Its error path tries to decide<br /> whether msg_tx names the local temporary message by comparing it with<br /> the current value of psock-&gt;cork.<br /> <br /> This comparison is unsafe when two threads send on the same socket:<br /> <br /> Thread A Thread B<br /> msg_tx = psock-&gt;cork<br /> sk_msg_alloc() fails<br /> sk_stream_wait_memory()<br /> releases the socket lock acquires the socket lock<br /> completes the cork<br /> psock-&gt;cork = NULL<br /> frees the cork<br /> reacquires the socket lock<br /> msg_tx != psock-&gt;cork<br /> sk_msg_free(msg_tx)<br /> <br /> The stale cork is therefore mistaken for the local temporary message<br /> and freed again. KASAN reported:<br /> <br /> BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50<br /> Read of size 4 at addr ffff88810c908800 by task poc/90<br /> Call Trace:<br /> sk_msg_free+0x49/0x50<br /> tcp_bpf_sendmsg+0x14f5/0x1cc0<br /> __sys_sendto+0x32c/0x3a0<br /> __x64_sys_sendto+0xdb/0x1b0<br /> Allocated by task 89:<br /> __kasan_kmalloc+0x8f/0xa0<br /> tcp_bpf_sendmsg+0x16b3/0x1cc0<br /> Freed by task 91:<br /> __kasan_slab_free+0x43/0x70<br /> kfree+0x131/0x3c0<br /> tcp_bpf_sendmsg+0xec3/0x1cc0<br /> <br /> msg_tx can only name the stack-local tmp or the shared cork. Check for<br /> tmp directly so a changed psock-&gt;cork cannot turn a shared message into<br /> an apparent local one.