In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues
When running `test_sockmap` selftests, the following warning appears:
WARNING: CPU: 2 PID: 197 at net/core/stream.c:205 sk_stream_kill_queues+0xd3/0xf0 Call Trace: <TASK> inet_csk_destroy_sock+0x55/0x110 tcp_rcv_state_process+0xd28/0x1380 ? tcp_v4_do_rcv+0x77/0x2c0 tcp_v4_do_rcv+0x77/0x2c0 __release_sock+0x106/0x130 __tcp_close+0x1a7/0x4e0 tcp_close+0x20/0x70 inet_release+0x3c/0x80 __sock_release+0x3a/0xb0 sock_close+0x14/0x20 __fput+0xa3/0x260 task_work_run+0x59/0xb0 exit_to_user_mode_prepare+0x1b3/0x1c0 syscall_exit_to_user_mode+0x19/0x50 do_syscall_64+0x48/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae
The root case is in commit 84472b436e76 ("bpf, sockmap: Fix more uncharged while msg has more_data"), where I used msg->sg.size to replace the tosend, causing breakage:
if (msg->apply_bytes && msg->apply_bytes < tosend) tosend = psock->apply_bytes;
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perf-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-debuginfoUpgrade kernel-develUpgrade bpftool-debuginfoUpgrade bpftoolUpgrade perfUpgrade kernel-tools-develUpgrade kernel-livepatch-5.15.79-51.138Upgrade python-perfUpgrade kernel-toolsUpgrade kernelUpgrade kernel-livepatch-5.10.155-138.670 | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-abi-stablelistsUpgrade kernelUpgrade python3-perfUpgrade bpftoolUpgrade kernel-tools-libsUpgrade kernel-tools | Oct 24, 2025 | Oct 23, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-iotUpgrade linux-azure-5.4Upgrade linux-hwe-5.15Upgrade linux-kvmUpgrade linux-intel-iotg-5.15Upgrade linux-oracleUpgrade linux-intel-iot-realtimeUpgrade linux-azure-fipsUpgrade linux-xilinx-zynqmpUpgrade linux-azure-5.15Upgrade linux-gcpUpgrade linux-hwe-5.4Upgrade linux-gcp-5.15Upgrade linux-nvidiaUpgrade linux-gcp-fipsUpgrade linux-aws-fipsUpgrade linux-gkeopUpgrade linux-azureUpgrade linux-intel-iotgUpgrade linux-ibmUpgrade linux-oracle-5.15Upgrade linux-gcp-5.4Upgrade linux-bluefieldUpgrade linux-awsUpgrade linux-gkeUpgrade linux-nvidia-tegra-5.15Upgrade linux-oracle-5.4Upgrade linuxUpgrade linux-aws-5.15Upgrade linux-lowlatencyUpgrade linux-fipsUpgrade linux-raspiUpgrade linux-raspi-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.4Upgrade linux-realtimeUpgrade linux-ibm-5.4Upgrade linux-riscv-5.15 | May 6, 2025 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub