In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure handshakereqsubmit() replaces sk->skdestruct but never restores it when submission fails before the request is hashed. handshakeskdestruct() then returns early and the original destructor never runs, leaking the socket. Restore skdestruct on the error path.