Description
In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()

sk_protocol lives in struct sock, not in struct sock_common. A timewait
or request sock handed to bpf_sock_destroy() by the tcp iterator is
neither, so reading sk->sk_protocol runs past the object:

==================================================================
BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0
Read of size 2 at addr ffff8881047d11b4 by task test_progs/428

Tainted: [W]=WARN
Call Trace:
<TASK>
dump_stack_lvl+0x91/0xf0
print_report+0xd1/0x630
kasan_report+0xf3/0x130
__asan_report_load2_noabort+0x14/0x30
bpf_sock_destroy+0xc7/0xe0
bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7
bpf_iter_run_prog+0x538/0xde0
bpf_iter_tcp_seq_show+0x26b/0x4b0
bpf_seq_read+0x424/0x1210
vfs_read+0x197/0xe40
ksys_read+0x119/0x240
__x64_sys_read+0x72/0xc0
x64_sys_call+0x647/0x27e0
do_syscall_64+0xe5/0x610
entry_SYSCALL_64_after_hwframe+0x76/0x7e

Only check sk_protocol on full socks. tcp_abort() already knows how to
deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it
never matched the code.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel crash leading to denial of service
Action: Update kernel
AI Analysis

Impact

The Linux kernel vulnerability arises from an out‑of‑bounds read of the sk_protocol field in bpf_sock_destroy(). The field resides in struct sock, but the code reads it from a struct sock_common that does not contain it. When a socket in TIME_WAIT or NEW_SYN_RECV state is passed to the BPF iterator, the kernel attempts to read past the end of the object, triggering a KASAN error and often resulting in a crash. This bug falls under the weakness of improper input validation (CWE‑20) and can lead to denial of service by crashing the kernel or an application that relies on the socket state.

Affected Systems

The flaw is present in all versions of the Linux kernel that have not incorporated the patch commit referenced in the advisory. The affected product is the Linux kernel, distributed by the Linux Foundation, for all architectures that implement BPF socket iterators.

Risk and Exploitability

The advisory does not list a KEV or an EPSS score, indicating that no widespread exploitation has been reported and the likelihood of accidental exploitation is low. Nevertheless, the vulnerability can be triggered by loading a BPF program that accesses sockets through the iterator interface, which is typically a local or privileged action. If an attacker can inject such a BPF program, they could cause a kernel crash and disrupt availability. The exploit requires kernel knowledge and the ability to load BPF code, so while the path is clear, the practical risk remains moderate until a patch is applied.

Generated by OpenCVE AI on October 9, 2026 at 09:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel version that contains the fix for bpf_sock_destroy, such as the latest stable release that includes commit 01b245ba or later.
  • Reboot the system so that the updated kernel is in use.
  • If your distribution has not yet provided an updated kernel, build and install the patched kernel from source, or apply the vendor’s security update package when it becomes available.

Generated by OpenCVE AI on October 9, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 09 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy() sk_protocol lives in struct sock, not in struct sock_common. A timewait or request sock handed to bpf_sock_destroy() by the tcp iterator is neither, so reading sk->sk_protocol runs past the object: ================================================================== BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0 Read of size 2 at addr ffff8881047d11b4 by task test_progs/428 Tainted: [W]=WARN Call Trace: <TASK> dump_stack_lvl+0x91/0xf0 print_report+0xd1/0x630 kasan_report+0xf3/0x130 __asan_report_load2_noabort+0x14/0x30 bpf_sock_destroy+0xc7/0xe0 bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7 bpf_iter_run_prog+0x538/0xde0 bpf_iter_tcp_seq_show+0x26b/0x4b0 bpf_seq_read+0x424/0x1210 vfs_read+0x197/0xe40 ksys_read+0x119/0x240 __x64_sys_read+0x72/0xc0 x64_sys_call+0x647/0x27e0 do_syscall_64+0xe5/0x610 entry_SYSCALL_64_after_hwframe+0x76/0x7e Only check sk_protocol on full socks. tcp_abort() already knows how to deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it never matched the code.
Title bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-09T07:34:23.097Z

Reserved: 2026-09-25T10:25:14.345Z

Link: CVE-2026-98384

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T08:16:56.940

Modified: 2026-10-09T08:16:56.940

Link: CVE-2026-98384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:00:06Z

Weaknesses
  • CWE-20

    Improper Input Validation