{"id":"CVE-2026-74589","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74589","summary":"bpf, sockmap: Fix sk_redir use-after-free in send verdict","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix sk_redir use-after-free in send verdict\n\nsk_psock_msg_verdict() takes a socket reference for psock->sk_redir.\ntcp_bpf_send_verdict() copies that pointer while holding the source socket\nlock, but does not take a reference for the local copy before dropping the\nlock around tcp_bpf_sendmsg_redir().\n\nWhen apply_bytes keeps the cached verdict active, another sendmsg() on the\nsame source socket can consume the remaining bytes and release the cached\nreference while the first thread still holds only the raw local pointer:\n\n  CPU 0                                  CPU 1\n  sk_redir = psock->sk_redir\n  apply_bytes remains nonzero\n  release_sock(sk)\n                                         lock_sock(sk)\n                                         apply_bytes reaches zero\n                                         psock->sk_redir = NULL\n                                         release_sock(sk)\n                                         tcp_bpf_sendmsg_redir(sk_redir)\n                                         sock_put(sk_redir)\n  tcp_bpf_sendmsg_redir(sk_redir)\n\nThe final sock_put() can free sk_redir before CPU 0 dereferences it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in tcp_bpf_sendmsg_redir+0xf39/0x1020\n  Read of size 8 at addr ffff888108537090 by task poc/87\n  Call Trace:\n   tcp_bpf_sendmsg_redir+0xf39/0x1020\n   tcp_bpf_sendmsg+0x977/0x1a50\n   __sys_sendto+0x32c/0x3a0\n   __x64_sys_sendto+0xdb/0x1b0\n  Allocated by task 85:\n   sk_prot_alloc+0x56/0x210\n   sk_clone+0x6f/0x14b0\n   inet_csk_clone_lock+0x24/0x740\n   tcp_create_openreq_child+0x25/0x2710\n   tcp_v4_syn_recv_sock+0x10a/0xe00\n  Freed by task 0:\n   __kasan_slab_free+0x43/0x70\n   slab_free_after_rcu_debug+0xa6/0x1e0\n   rcu_core+0x50a/0x1850\n  Last potentially related work creation:\n   __sk_destruct+0x3da/0x540\n   sk_psock_destroy+0x81e/0xab0\n   process_one_work+0x63a/0x1070\n\nTake a temporary socket reference while the source socket lock still\nprotects psock->sk_redir, and drop it after tcp_bpf_sendmsg_redir()\nreturns.  This keeps each unlocked use independent of cached-verdict\nownership.","published":"2026-08-22T15:31:41.177Z","modified":"2026-08-24T11:46:58.374089239Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"5.10.265"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1cec526cf0a2227395f2c2f4b671cb052ff0b00e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/41b7da0cb72ca5aa1e62b68dab323d0791fc6bdf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4c9d9aa809c261dc0490a0e19d675f7e8e4c85bf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/90a19b0894ba79a699b48cf44421b36fbd566e99"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9b4fbc371a6ecf1b4e43b5a629015cc0830d8de3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a14e4ef1d90c3418f01b3b6b8fd3a40a0a208a10"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a76624733730e541e4955fdecf506af2f6b20558"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d192cff2a37d59206dabe6ec2e60ceac6271f274"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74589.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74589"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T11:46:58.374089239Z"}}