PT-2026-107503 · Linux · Linux
CVE-2026-98374
·
Publicado
2026-10-07
·
Atualizado
2026-10-07
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix use-after-free of retransmit skb hint in tcp send synack()
When tcp send synack() replaces the cloned SYN skb at the head of the
retransmit queue with a copy, it frees the original with
tcp rtx queue unlink and free() and only repairs tp->highest sack.
tp->retransmit skb hint keeps pointing at the freed
skbuff fclone cache object.
The dangling hint is read in tcp verify retransmit hint() and used as
the root of the rbtree walk in tcp xmit retransmit queue(). An
unprivileged TFO client (sendmsg(MSG FASTOPEN)) can arm the hint with
an attacker-supplied ICMP fragmentation-needed message, after which a
simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp mark skb lost (net/ipv4/tcp input.c:1316)
Read of size 4 at addr ffff88800604d928 by task swapper/1/0
Call Trace:
tcp mark skb lost (net/ipv4/tcp input.c:1316)
tcp simple retransmit (net/ipv4/tcp input.c:3158)
tcp v4 err (net/ipv4/tcp ipv4.c:587)
Sync the hint to the copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux