Executive brief
The Linux kernel's network packet routing system (sockmap) contains a race condition that can allow a socket pointer to be freed while still in use. An attacker with local access could exploit this to cause a denial of service or potentially execute arbitrary code by triggering the use-after-free condition across multiple concurrent send operations.
Technical details
The vulnerability is a use-after-free in tcp_bpf_sendmsg_verdict() within the sockmap subsystem. The tcp_bpf_send_verdict() function copies a socket reference (sk_redir) from psock while holding the source socket lock, but fails to increment the reference count before releasing the lock. When apply_bytes policy keeps the verdict cached, a concurrent sendmsg() on the same socket can decrement the reference count and free sk_redir while the first thread still holds an unprotected local pointer. This leads to use-after-free when the first thread attempts to dereference the freed socket. The attack requires local unprivileged socket access and careful timing of concurrent operations. The fix involves taking a temporary socket reference while the lock protects psock->sk_redir, then releasing it after tcp_bpf_sendmsg_redir() completes.
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2026-08-22: disclosed