CVE-2026-68284
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
17/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()<br />
<br />
tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which<br />
drops and reacquires the socket lock. Its error path tries to decide<br />
whether msg_tx names the local temporary message by comparing it with<br />
the current value of psock->cork.<br />
<br />
This comparison is unsafe when two threads send on the same socket:<br />
<br />
Thread A Thread B<br />
msg_tx = psock->cork<br />
sk_msg_alloc() fails<br />
sk_stream_wait_memory()<br />
releases the socket lock acquires the socket lock<br />
completes the cork<br />
psock->cork = NULL<br />
frees the cork<br />
reacquires the socket lock<br />
msg_tx != psock->cork<br />
sk_msg_free(msg_tx)<br />
<br />
The stale cork is therefore mistaken for the local temporary message<br />
and freed again. KASAN reported:<br />
<br />
BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50<br />
Read of size 4 at addr ffff88810c908800 by task poc/90<br />
Call Trace:<br />
sk_msg_free+0x49/0x50<br />
tcp_bpf_sendmsg+0x14f5/0x1cc0<br />
__sys_sendto+0x32c/0x3a0<br />
__x64_sys_sendto+0xdb/0x1b0<br />
Allocated by task 89:<br />
__kasan_kmalloc+0x8f/0xa0<br />
tcp_bpf_sendmsg+0x16b3/0x1cc0<br />
Freed by task 91:<br />
__kasan_slab_free+0x43/0x70<br />
kfree+0x131/0x3c0<br />
tcp_bpf_sendmsg+0xec3/0x1cc0<br />
<br />
msg_tx can only name the stack-local tmp or the shared cork. Check for<br />
tmp directly so a changed psock->cork cannot turn a shared message into<br />
an apparent local one.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2d66a033864e27ab8d5e44cb36f31d9d2413bee4
- https://git.kernel.org/stable/c/752b1159ed5d0c48fe169a3721b96660a9822aa1
- https://git.kernel.org/stable/c/786d690257ec7a0c839f8710456e444ce3f1348b
- https://git.kernel.org/stable/c/cde4d6bcd9b73073c66498f6723c7b364c4dbc18
- https://git.kernel.org/stable/c/ee762f684eefa59de34d9ed93cab08336e834f47



