PT-2026-107503 · Linux · Linux

CVE-2026-98374

·

Publicado

2026-10-07

·

Atualizado

2026-10-07

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix use-after-free of retransmit skb hint in tcp send synack()
When tcp send synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp rtx queue unlink and free() and only repairs tp->highest sack. tp->retransmit skb hint keeps pointing at the freed skbuff fclone cache object.
The dangling hint is read in tcp verify retransmit hint() and used as the root of the rbtree walk in tcp xmit retransmit queue(). An unprivileged TFO client (sendmsg(MSG FASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp mark skb lost (net/ipv4/tcp input.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcp mark skb lost (net/ipv4/tcp input.c:1316) tcp simple retransmit (net/ipv4/tcp input.c:3158) tcp v4 err (net/ipv4/tcp ipv4.c:587)
Sync the hint to the copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98374

Produtos afetados

Linux