Answer in brief
CVE-2026-68284 records a Unknown severity vulnerability in bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=604326b41a6fb9b4a78b6179335decee0365cd8c <ee762f684eefa59de34d9ed93cab08336e834f47 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <cde4d6bcd9b73073c66498f6723c7b364c4dbc18 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <786d690257ec7a0c839f8710456e444ce3f1348b || >=604326b41a6fb9b4a78b6179335decee0365cd8c <752b1159ed5d0c48fe169a3721b96660a9822aa1 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <2d66a033864e27ab8d5e44cb36f31d9d2413bee4 | ee762f684eefa59de34d9ed93cab08336e834f47, cde4d6bcd9b73073c66498f6723c7b364c4dbc18, 786d690257ec7a0c839f8710456e444ce3f1348b, 752b1159ed5d0c48fe169a3721b96660a9822aa1, 2d66a033864e27ab8d5e44cb36f31d9d2413bee4 |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported: BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0 msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68284 records a Unknown severity vulnerability in bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=604326b41a6fb9b4a78b6179335decee0365cd8c <ee762f684eefa59de34d9ed93cab08336e834f47 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <cde4d6bcd9b73073c66498f6723c7b364c4dbc18 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <786d690257ec7a0c839f8710456e444ce3f1348b || >=604326b41a6fb9b4a78b6179335decee0365cd8c <752b1159ed5d0c48fe169a3721b96660a9822aa1 || >=604326b41a6fb9b4a78b6179335decee0365cd8c <2d66a033864e27ab8d5e44cb36f31d9d2413bee4 | ee762f684eefa59de34d9ed93cab08336e834f47, cde4d6bcd9b73073c66498f6723c7b364c4dbc18, 786d690257ec7a0c839f8710456e444ce3f1348b, 752b1159ed5d0c48fe169a3721b96660a9822aa1, 2d66a033864e27ab8d5e44cb36f31d9d2413bee4 |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported: BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0 msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.
Quoted source text, attributed separately from HOL analysis.