PT-2026-106605 · Linux · Linux

CVE-2026-98276

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: lock the socket in sock gettstamp()
sk->sk flags must only be changed while holding the socket lock, because sock set flag() and sock reset flag() use non atomic operations ( set bit() and clear bit()).
sock gettstamp() is one of the last places where a bit of sk->sk flags is changed from a syscall without owning the socket lock, through sock enable timestamp(sk, SOCK TIMESTAMP).
sk set memalloc() and sk clear memalloc() also change sk->sk flags without the socket lock, but their callers (nbd, iscsi tcp, nvme-tcp, sunrpc, wireguard) need a careful audit, this will be addressed in a separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free caused by this bug: a SIOCGSTAMPNS NEW ioctl racing with bind() can cancel the SOCK RCU FREE bit that udp lib get port() just set, because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS NEW)

read sk flags = F read sk flags = F compute F | BIT(SOCK RCU FREE) compute F | BIT(SOCK TIMESTAMP) store F | BIT(SOCK RCU FREE) sk add node rcu(sk, ...) store F | BIT(SOCK TIMESTAMP)
After the lost update, SOCK RCU FREE is clear while the socket is visible to lockless UDP receive lookups. sk destruct() then frees the socket immediately instead of waiting for a RCU grace period, while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4 pktinfo prepare+0x30/0x410 Read of size 8 at addr ffff888008806610 by task exploit/207 CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1 ipv4 pktinfo prepare+0x30/0x410 udp queue rcv one skb+0x51c/0x1180 udp unicast rcv skb+0x109/0x350 ip protocol deliver rcu+0x14b/0x310 ip local deliver finish+0x29d/0x390 ip local deliver+0x24d/0x2a0
Only grab the socket lock when SOCK TIMESTAMP has to be set, to keep the common case lockless.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98276

Produtos afetados

Linux