PT-2026-107503 · Linux · Linux

CVE-2026-98374

·

Published

2026-10-07

·

Updated

2026-10-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix use-after-free of retransmit skb hint in tcp send synack()
When tcp send synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp rtx queue unlink and free() and only repairs tp->highest sack. tp->retransmit skb hint keeps pointing at the freed skbuff fclone cache object.
The dangling hint is read in tcp verify retransmit hint() and used as the root of the rbtree walk in tcp xmit retransmit queue(). An unprivileged TFO client (sendmsg(MSG FASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcp mark skb lost (net/ipv4/tcp input.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcp mark skb lost (net/ipv4/tcp input.c:1316) tcp simple retransmit (net/ipv4/tcp input.c:3158) tcp v4 err (net/ipv4/tcp ipv4.c:587)
Sync the hint to the copy.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98374

Affected Products

Linux