In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues
When running `test_sockmap` selftests, the following warning appears:
WARNING: CPU: 2 PID: 197 at net/core/stream.c:205 sk_stream_kill_queues+0xd3/0xf0 Call Trace: <TASK> inet_csk_destroy_sock+0x55/0x110 tcp_rcv_state_process+0xd28/0x1380 ? tcp_v4_do_rcv+0x77/0x2c0 tcp_v4_do_rcv+0x77/0x2c0 __release_sock+0x106/0x130 __tcp_close+0x1a7/0x4e0 tcp_close+0x20/0x70 inet_release+0x3c/0x80 __sock_release+0x3a/0xb0 sock_close+0x14/0x20 __fput+0xa3/0x260 task_work_run+0x59/0xb0 exit_to_user_mode_prepare+0x1b3/0x1c0 syscall_exit_to_user_mode+0x19/0x50 do_syscall_64+0x48/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae
The root case is in commit 84472b436e76 ("bpf, sockmap: Fix more uncharged while msg has more_data"), where I used msg->sg.size to replace the tosend, causing breakage:
if (msg->apply_bytes && msg->apply_bytes < tosend) tosend = psock->apply_bytes;
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfo-common-aarch64Upgrade kernel-headersUpgrade kernel-tools-debuginfoUpgrade python-perf-debuginfoUpgrade perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-debuginfoUpgrade kernel-develUpgrade kernel-livepatch-5.15.79-51.138Upgrade perfUpgrade kernel-tools-develUpgrade kernel-livepatch-5.10.155-138.670Upgrade kernelUpgrade python-perfUpgrade bpftoolUpgrade kernel-tools | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade bpftoolUpgrade kernel-tools-libsUpgrade kernelUpgrade python3-perfUpgrade kernel-toolsUpgrade kernel-abi-stablelists | Oct 24, 2025 | Oct 23, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-oracleUpgrade linux-xilinx-zynqmpUpgrade linux-azure-fipsUpgrade linux-hwe-5.4Upgrade linux-gcp-5.15Upgrade linux-intel-iotgUpgrade linux-gkeopUpgrade linux-azure-5.4Upgrade linux-hwe-5.15Upgrade linux-nvidiaUpgrade linux-iotUpgrade linux-azureUpgrade linux-azure-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-aws-fipsUpgrade linux-gcp-fipsUpgrade linux-intel-iot-realtimeUpgrade linux-gcp-5.4Upgrade linux-kvmUpgrade linux-ibmUpgrade linux-oracle-5.15Upgrade linux-realtimeUpgrade linux-awsUpgrade linux-lowlatencyUpgrade linux-fipsUpgrade linux-riscv-5.15Upgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-oracle-5.4Upgrade linux-nvidia-tegra-5.15Upgrade linux-ibm-5.4Upgrade linux-aws-5.4Upgrade linux-aws-5.15Upgrade linux-gkeUpgrade linux-lowlatency-hwe-5.15Upgrade linux-raspiUpgrade linux | May 6, 2025 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub