PT-2026-107503 · Linux · Linux
CVE-2026-98374
·
Published
2026-10-07
·
Updated
2026-10-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix use-after-free of retransmit skb hint in tcp send synack()
When tcp send synack() replaces the cloned SYN skb at the head of the
retransmit queue with a copy, it frees the original with
tcp rtx queue unlink and free() and only repairs tp->highest sack.
tp->retransmit skb hint keeps pointing at the freed
skbuff fclone cache object.
The dangling hint is read in tcp verify retransmit hint() and used as
the root of the rbtree walk in tcp xmit retransmit queue(). An
unprivileged TFO client (sendmsg(MSG FASTOPEN)) can arm the hint with
an attacker-supplied ICMP fragmentation-needed message, after which a
simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp mark skb lost (net/ipv4/tcp input.c:1316)
Read of size 4 at addr ffff88800604d928 by task swapper/1/0
Call Trace:
tcp mark skb lost (net/ipv4/tcp input.c:1316)
tcp simple retransmit (net/ipv4/tcp input.c:3158)
tcp v4 err (net/ipv4/tcp ipv4.c:587)
Sync the hint to the copy.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux