Junglewise Threat Intelligence

CVE-2026-74589: Linux kernel use-after-free in sockmap send verdict

CVE-2026-74589 · Severity: high · CVSS 8.4 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's network packet routing system (sockmap) contains a race condition that can allow a socket pointer to be freed while still in use. An attacker with local access could exploit this to cause a denial of service or potentially execute arbitrary code by triggering the use-after-free condition across multiple concurrent send operations.

Technical details

The vulnerability is a use-after-free in tcp_bpf_sendmsg_verdict() within the sockmap subsystem. The tcp_bpf_send_verdict() function copies a socket reference (sk_redir) from psock while holding the source socket lock, but fails to increment the reference count before releasing the lock. When apply_bytes policy keeps the verdict cached, a concurrent sendmsg() on the same socket can decrement the reference count and free sk_redir while the first thread still holds an unprotected local pointer. This leads to use-after-free when the first thread attempts to dereference the freed socket. The attack requires local unprivileged socket access and careful timing of concurrent operations. The fix involves taking a temporary socket reference while the lock protects psock->sk_redir, then releasing it after tcp_bpf_sendmsg_redir() completes.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-08-22: disclosed

Related threats