In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues
When running `test_sockmap` selftests, the following warning appears:
WARNING: CPU: 2 PID: 197 at net/core/stream.c:205 sk_stream_kill_queues+0xd3/0xf0 Call Trace: <TASK> inet_csk_destroy_sock+0x55/0x110 tcp_rcv_state_process+0xd28/0x1380 ? tcp_v4_do_rcv+0x77/0x2c0 tcp_v4_do_rcv+0x77/0x2c0 __release_sock+0x106/0x130 __tcp_close+0x1a7/0x4e0 tcp_close+0x20/0x70 inet_release+0x3c/0x80 __sock_release+0x3a/0xb0 sock_close+0x14/0x20 __fput+0xa3/0x260 task_work_run+0x59/0xb0 exit_to_user_mode_prepare+0x1b3/0x1c0 syscall_exit_to_user_mode+0x19/0x50 do_syscall_64+0x48/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae
The root case is in commit 84472b436e76 ("bpf, sockmap: Fix more uncharged while msg has more_data"), where I used msg->sg.size to replace the tosend, causing breakage:
if (msg->apply_bytes && msg->apply_bytes < tosend) tosend = psock->apply_bytes;
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bpftool-debuginfoUpgrade kernel-develUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade python-perf-debuginfoUpgrade kernel-debuginfoUpgrade perf-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-livepatch-5.10.155-138.670Upgrade kernel-tools-develUpgrade kernelUpgrade perfUpgrade bpftoolUpgrade kernel-livepatch-5.15.79-51.138Upgrade python-perfUpgrade kernel-tools | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-abi-stablelistsUpgrade bpftoolUpgrade kernel-tools-libsUpgrade kernel-toolsUpgrade kernelUpgrade python3-perf | Oct 24, 2025 | Oct 23, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-nvidiaUpgrade linux-xilinx-zynqmpUpgrade linux-oracleUpgrade linux-azure-fipsUpgrade linux-intel-iot-realtimeUpgrade linux-hwe-5.15Upgrade linux-oracle-5.15Upgrade linux-gcp-5.4Upgrade linux-ibmUpgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-aws-fipsUpgrade linux-azure-5.15Upgrade linux-intel-iotgUpgrade linux-azureUpgrade linux-gcp-5.15Upgrade linux-hwe-5.4Upgrade linux-gkeopUpgrade linux-iotUpgrade linux-gcp-fipsUpgrade linux-gcpUpgrade linux-azure-5.4Upgrade linux-riscv-5.15Upgrade linux-bluefieldUpgrade linux-ibm-5.4Upgrade linux-raspiUpgrade linux-aws-5.4Upgrade linux-awsUpgrade linuxUpgrade linux-oracle-5.4Upgrade linux-aws-5.15Upgrade linux-fipsUpgrade linux-gkeUpgrade linux-nvidia-tegra-5.15Upgrade linux-raspi-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-lowlatencyUpgrade linux-realtime | May 6, 2025 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub