PT-2026-108770 · Linux · Linux
CVE-2026-98384
·
Published
2026-10-09
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix out-of-bounds read of sk protocol in bpf sock destroy()
sk protocol lives in struct sock, not in struct sock common. A timewait
or request sock handed to bpf sock destroy() by the tcp iterator is
neither, so reading sk->sk protocol runs past the object:
==================================================================
BUG: KASAN: slab-out-of-bounds in bpf sock destroy+0xc7/0xe0
Read of size 2 at addr ffff8881047d11b4 by task test progs/428
Tainted: [W]=WARN
Call Trace:
dump stack lvl+0x91/0xf0
print report+0xd1/0x630
kasan report+0xf3/0x130
asan report load2 noabort+0x14/0x30
bpf sock destroy+0xc7/0xe0
bpf prog c3dd61f9d9cd9f37 iter tcp6 timewait+0x9f/0xb7
bpf iter run prog+0x538/0xde0
bpf iter tcp seq show+0x26b/0x4b0
bpf seq read+0x424/0x1210
vfs read+0x197/0xe40
ksys read+0x119/0x240
x64 sys read+0x72/0xc0
x64 sys call+0x647/0x27e0
do syscall 64+0xe5/0x610
entry SYSCALL 64 after hwframe+0x76/0x7e
Only check sk protocol on full socks. tcp abort() already knows how to
deal with TIME WAIT and NEW SYN RECV socks. Also fix the comment, it
never matched the code.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux