Executive brief
A vulnerability in the Linux kernel's networking component can cause a system crash (kernel panic) when specific security hardening features are enabled. This occurs when an application attempts to read error messages from a network socket, such as during timestamp reporting. While it does not directly expose data, it can be used by a local user to disrupt system availability and cause a denial-of-service.
Technical details
A usercopy hardening violation exists in 'sock_recv_errqueue' due to 'skbuff_fclone_cache' lacking a whitelisted usercopy region for the 'cb[]' field. When TCP allocates an sk_buff using 'alloc_skb_fclone()' and it is subsequently cloned and queued for error reporting (e.g., timestamping), calling 'put_cmsg()' to copy error data to userspace triggers a kernel BUG() in '__check_heap_object()'. This occurs because the memory being accessed is not explicitly marked as safe for copying to userspace. The fix involves using a local stack variable as a bounce buffer to bypass the hardening check.
Affected products
- Linux Linux Kernel 5.11 to 5.15.198, 6.2 to 6.6, 6.13 to 6.18.6, 6.19-rc1 to 6.19-rc4
Timeline
- 2025-12-24: patched: Initial patch authored
- 2026-01-21: disclosed: CVE published
References
- https://git.kernel.org/stable/c/005671c60fcf1dbdb8bddf12a62568fd5e4ec391
- https://git.kernel.org/stable/c/2a71a1a8d0ed718b1c7a9ac61f07e5755c47ae20
- https://git.kernel.org/stable/c/582a5e922a9652fcbb7d0165c95d5b20aa37575d
- https://git.kernel.org/stable/c/88dd6be7ebb3153b662c2cebcb06e032a92857f5
- https://git.kernel.org/stable/c/8c6901aa29626e35045130bac09b75f791acca85
- https://git.kernel.org/stable/c/c655d2167bf014d4c61b4faeca59b60ff9b9f6b1
- https://git.kernel.org/stable/c/e00b169eaac5f7cdbf710c354c8fa76d02009115