CVE-2026-68284
Last modified
CVE-2026-68284 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported: BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0 msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 604326b41a6fb9b4a78b6179335decee0365cd8c, < ee762f684eefa59de34d9ed93cab08336e834f47; >= 604326b41a6fb9b4a78b6179335decee0365cd8c, < cde4d6bcd9b73073c66498f6723c7b364c4dbc18; >= 604326b41a6fb9b4a78b6179335decee0365cd8c, < 786d690257ec7a0c839f8710456e444ce3f1348b; >= 604326b41a6fb9b4a78b6179335decee0365cd8c, < 752b1159ed5d0c48fe169a3721b96660a9822aa1; >= 604326b41a6fb9b4a78b6179335decee0365cd8c, < 2d66a033864e27ab8d5e44cb36f31d9d2413bee4 |
| Linux | Linux | 4.20 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68284?
How severe is CVE-2026-68284?
How do I fix CVE-2026-68284?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68279In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6828The Fluent Forms – Customizable Contact Forms, Survey, Quiz,…6.4
- CVE-2026-68280In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68281In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68282In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68283In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68285In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68286In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68287In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68288In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68289In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6829nesquena hermes-webui contains a trust-boundary failure vuln…6.3
Are you affected by CVE-2026-68284?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
