CVE-2026-74268

Source
https://cve.org/CVERecord?id=CVE-2026-74268
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74268.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74268
Downstream
Published
2026-08-15T05:57:42.920Z
Modified
2026-08-18T03:56:28.026734734Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
tcp: clear sock_ops cb flags before force-closing a child socket
Details

In the Linux kernel, the following vulnerability has been resolved:

tcp: clear sock_ops cb flags before force-closing a child socket

A child socket inherits the listener's bpfsockopscbflags via skclonelock(). If its setup fails in tcpv4synrecvsock() / tcpv6synrecvsock(), the child is freed through putandexit, where inetcskprepareforcedclose() drops the socket lock and tcp_done() runs without it.

If BPFSOCKOPSSTATECBFLAG was inherited, tcpdone() -> tcpsetstate() calls tcpcallbpf(), which expects the lock and trips sockownedby_me():

WARNING: include/net/sock.h:1799 at tcpsetstate+0x433/0x550 RIP: 0010:tcpsetstate+0x433/0x550 include/net/sock.h:1799 Call Trace: <IRQ> tcpdone+0xba/0x250 net/ipv4/tcp.c:5095 tcpv4synrecvsock+0x850/0xa50 net/ipv4/tcpipv4.c:1787 tcpcheckreq+0xf30/0x1360 net/ipv4/tcpminisocks.c:926 tcpv4rcv+0x1047/0x1b50 net/ipv4/tcpipv4.c:2164 </IRQ>

The child is freed before it is ever established, so it should run no sockops callback. Clear its cb flags in inetcskpreparefordestroysock(), the common point for the IPv4, IPv6 and chtls forced-close paths and for the MPTCP ->synrecvsock() failure path (disposechild), which reaches tcpdone() on a child that was never established too.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74268.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d44874910a26f3a8f81edf873a2473363f07f660
Fixed
ce311bd2e36596f0aa2c92ca86fb3e019ac57eae
Fixed
8874dafc9099bc49c2e5ebba030f85d276421f92
Fixed
990348e5bb457697c2f1f7f7b65154a3334d9d2b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74268.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74268.json"