CVE-2026-68290
Last modified
CVE-2026-68290 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: rds: tcp: unregister sysctl before tearing down listen socket rds_tcp_exit_net() frees the per-netns RDS TCP listen socket via rds_tcp_kill_sock() before unregistering the per-netns sysctl table. Since rds_tcp_skbuf_handler() derives the netns from rtn->rds_tcp_listen_sock->sk, a concurrent sysctl write can race with netns teardown and dereference the freed socket/sk. KASAN reports the race as: BUG: KASAN: slab-use-after-free in rds_tcp_skbuf_handler+0x2aa/0x2e0 rds_tcp_skbuf_handler net/rds/tcp.c:721 proc_sys_call_handler fs/proc/proc_sysctl.c vfs_write fs/read_write.c __x64_sys_pwrite64 fs/read_write.c Fix this by unregistering the RDS TCP sysctl table before calling rds_tcp_kill_sock().
Description
In the Linux kernel, the following vulnerability has been resolved: rds: tcp: unregister sysctl before tearing down listen socket rds_tcp_exit_net() frees the per-netns RDS TCP listen socket via rds_tcp_kill_sock() before unregistering the per-netns sysctl table. Since rds_tcp_skbuf_handler() derives the netns from rtn->rds_tcp_listen_sock->sk, a concurrent sysctl write can race with netns teardown and dereference the freed socket/sk. KASAN reports the race as: BUG: KASAN: slab-use-after-free in rds_tcp_skbuf_handler+0x2aa/0x2e0 rds_tcp_skbuf_handler net/rds/tcp.c:721 proc_sys_call_handler fs/proc/proc_sysctl.c vfs_write fs/read_write.c __x64_sys_pwrite64 fs/read_write.c Fix this by unregistering the RDS TCP sysctl table before calling rds_tcp_kill_sock(). unregister_net_sysctl_table() prevents new sysctl handlers from starting and waits for in-flight handlers to finish, so the listen socket can then be released safely. The fix was tested against the linked reproducer.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= de8d6de0ee27be4b2b1e5b06f04aeacbabbba492, < 80fffed08dc1c10e971066941d2daa56253f1552; >= 7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c, < 16df2d154ec82e2f7e7585b4fa154751ba37729a; >= 7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c, < 3aa13fe0c1bb7bc5312f878e61523e5d8cf3f85d; >= 7f5611cbc4871c7fb1ad36c2e5a9edad63dca95c, < 167e54c703ccd4fa028feb568b0d1002020cff86; >= 6.12.10, < 6.12.101 |
| Linux | Linux | 6.13 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68290?
How severe is CVE-2026-68290?
How do I fix CVE-2026-68290?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68285In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68286In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68287In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68288In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68289In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6829nesquena hermes-webui contains a trust-boundary failure vuln…6.3
- CVE-2026-68291In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68292In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68293In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68294In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68295In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68296In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
