PT-2026-106605 · Linux · Linux
CVE-2026-98276
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: lock the socket in sock gettstamp()
sk->sk flags must only be changed while holding the socket lock,
because sock set flag() and sock reset flag() use non atomic
operations ( set bit() and clear bit()).
sock gettstamp() is one of the last places where a bit of sk->sk flags
is changed from a syscall without owning the socket lock, through
sock enable timestamp(sk, SOCK TIMESTAMP).
sk set memalloc() and sk clear memalloc() also change sk->sk flags
without the socket lock, but their callers (nbd, iscsi tcp, nvme-tcp,
sunrpc, wireguard) need a careful audit, this will be addressed in a
separate patch.
Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free
caused by this bug: a SIOCGSTAMPNS NEW ioctl racing with bind()
can cancel the SOCK RCU FREE bit that udp lib get port() just set,
because both threads perform a read-modify-write on the same word.
CPU 0 (bind) CPU 1 (SIOCGSTAMPNS NEW)
read sk flags = F read sk flags = F
compute F | BIT(SOCK RCU FREE) compute F | BIT(SOCK TIMESTAMP)
store F | BIT(SOCK RCU FREE)
sk add node rcu(sk, ...)
store F | BIT(SOCK TIMESTAMP)
After the lost update, SOCK RCU FREE is clear while the socket is
visible to lockless UDP receive lookups. sk destruct() then frees
the socket immediately instead of waiting for a RCU grace period,
while the receive path still holds a reference-less pointer to it:
BUG: KASAN: slab-use-after-free in ipv4 pktinfo prepare+0x30/0x410
Read of size 8 at addr ffff888008806610 by task exploit/207
CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1
ipv4 pktinfo prepare+0x30/0x410
udp queue rcv one skb+0x51c/0x1180
udp unicast rcv skb+0x109/0x350
ip protocol deliver rcu+0x14b/0x310
ip local deliver finish+0x29d/0x390
ip local deliver+0x24d/0x2a0
Only grab the socket lock when SOCK TIMESTAMP has to be set,
to keep the common case lockless.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux