In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Fix repeated calls to sock_put() when msg has more_data
In tcp_bpf_send_verdict() redirection, the eval variable is assigned to __SK_REDIRECT after the apply_bytes data is sent, if msg has more_data, sock_put() will be called multiple times.
We should reset the eval variable to __SK_NONE every time more_data starts.
This causes:
IPv4: Attempt to release TCP socket in state 1 00000000b4c925d7 ------------[ cut here ]------------ refcount_t: addition on 0; use-after-free. WARNING: CPU: 5 PID: 4482 at lib/refcount.c:25 refcount_warn_saturate+0x7d/0x110 Modules linked in: CPU: 5 PID: 4482 Comm: sockhash_bypass Kdump: loaded Not tainted 6.0.0 #1 Hardware name: Red Hat KVM, BIOS 1.11.0-2.el7 04/01/2014 Call Trace: <TASK> __tcp_transmit_skb+0xa1b/0xb90 ? __alloc_skb+0x8c/0x1a0 ? __kmalloc_node_track_caller+0x184/0x320 tcp_write_xmit+0x22a/0x1110 __tcp_push_pending_frames+0x32/0xf0 do_tcp_sendpages+0x62d/0x640 tcp_bpf_push+0xae/0x2c0 tcp_bpf_sendmsg_redir+0x260/0x410 ? preempt_count_add+0x70/0xa0 tcp_bpf_send_verdict+0x386/0x4b0 tcp_bpf_sendmsg+0x21b/0x3b0 sock_sendmsg+0x58/0x70 __sys_sendto+0xfa/0x170 ? xfd_validate_state+0x1d/0x80 ? switch_fpu_return+0x59/0xe0 __x64_sys_sendto+0x24/0x30 do_syscall_64+0x37/0x90 entry_SYSCALL_64_after_hwframe+0x63/0xcd
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-headersUpgrade kernel-livepatch-5.15.86-53.137Upgrade perfUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade python-perfUpgrade kernel-livepatch-5.10.165-143.735Upgrade python-perf-debuginfoUpgrade kernel-debuginfoUpgrade kernelUpgrade kernel-debuginfo-common-x86_64Upgrade bpftoolUpgrade kernel-tools-debuginfoUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64Upgrade bpftool-debuginfo | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | Oct 9, 2025 | Oct 9, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-perfUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-abi-stablelistsUpgrade kernel-tools-libsUpgrade kernel | Feb 3, 2026 | Feb 2, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 7, 2025 |
| Ubuntu | — | Upgrade linux-riscv-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-oracle-5.4Upgrade linux-fipsUpgrade linux-gcpUpgrade linux-ibm-5.4Upgrade linux-aws-5.4Upgrade linuxUpgrade linux-intel-iotgUpgrade linux-nvidia-tegra-5.15Upgrade linux-aws-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-awsUpgrade linux-oracle-5.15Upgrade linux-raspi-5.4Upgrade linux-gkeUpgrade linux-raspiUpgrade linux-lowlatencyUpgrade linux-bluefieldUpgrade linux-iotUpgrade linux-hwe-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-ibmUpgrade linux-gcp-fipsUpgrade linux-hwe-5.4Upgrade linux-gcp-5.4Upgrade linux-azure-fipsUpgrade linux-realtimeUpgrade linux-intel-iotg-5.15Upgrade linux-gkeopUpgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-kvmUpgrade linux-azure-5.4Upgrade linux-gcp-5.15Upgrade linux-azure-5.15Upgrade linux-aws-fipsUpgrade linux-azure | Oct 10, 2025 | Oct 7, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Oct 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub