In the Linux kernel, the following vulnerability has been resolved:
udp: clear skb->dev before running a sockmap verdict
On the UDP receive path skb->dev is repurposed as dev_scratch (the truesize/state cache set by udp_set_dev_scratch()), through the union { struct net_device *dev; unsigned long dev_scratch; } in sk_buff.
When a UDP socket is in a sockmap, sk_data_ready is sk_psock_verdict_data_ready(), which calls udp_read_skb() -> recv_actor() (sk_psock_verdict_recv) to run the attached SK_SKB verdict program in softirq. If that program calls a socket-lookup helper (bpf_sk_lookup_tcp/udp, bpf_skc_lookup_tcp), bpf_skc_lookup() does:
if (skb->dev) caller_net = dev_net(skb->dev);
skb->dev still holds the dev_scratch value (a non-NULL integer), so dev_net() dereferences it as a struct net_device * and the kernel takes a general protection fault on a non-canonical address in softirq:
Oops: general protection fault, probably for non-canonical address 0x1010000800004a0 CPU: 1 UID: 0 PID: 1406 Comm: syz.2.19 Not tainted 7.1.0-rc6 #1 PREEMPT(full) RIP: 0010:bpf_skc_lookup net/core/filter.c:7033 [inline] RIP: 0010:bpf_sk_lookup+0x45/0x160 net/core/filter.c:7047 Call Trace: <IRQ> bpf_prog_4675cb904b7071f8+0x12e/0x14e bpf_prog_run_pin_on_cpu+0xc6/0x1f0 sk_psock_verdict_recv+0x1ba/0x350 udp_read_skb+0x31a/0x370 sk_psock_verdict_data_ready+0x2e3/0x600 __udp_enqueue_schedule_skb+0x4c8/0x650 udpv6_queue_rcv_one_skb+0x3ec/0x740 udp6_unicast_rcv_skb+0x11d/0x140 ip6_protocol_deliver_rcu+0x61e/0x950 ip6_input_finish+0xa9/0x150 NF_HOOK+0x286/0x2f0 ip6_input+0x117/0x220 NF_HOOK+0x286/0x2f0 __netif_receive_skb+0x85/0x200 process_backlog+0x374/0x9a0 __napi_poll+0x4f/0x1c0 net_rx_action+0x3b0/0x770 handle_softirqs+0x15a/0x460 do_softirq+0x57/0x80 </IRQ>
The rmem charge that dev_scratch accounted for is released by skb_recv_udp() on dequeue, just above, so the scratch is dead by the time recv_actor() runs. Clear skb->dev so bpf_skc_lookup() falls back to sock_net(skb->sk), which skb_set_owner_sk_safe() set just above.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perfUpgrade perf6.18Upgrade kernel6.12-develUpgrade kernel-develUpgrade kernel6.18-develUpgrade kernel6.12-headersUpgrade python3-perf6.12-debuginfoUpgrade kernel-tools-develUpgrade python3-perf-debuginfoUpgrade kernel6.18-tools-develUpgrade python3-perfUpgrade kernel6.18-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-modules-extra-commonUpgrade kernel6.12-tools-debuginfoUpgrade kernel6.18-headersUpgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade kernel-tools-debuginfoUpgrade bpftoolUpgrade kernel6.18-modules-extra-commonUpgrade bpftool6.18Upgrade kernel-livepatch-6.1.176-220.358Upgrade kernel6.18Upgrade perf6.12-debuginfoUpgrade kernel-debuginfoUpgrade kernelUpgrade python3-perf6.12Upgrade python3-perf6.18Upgrade kernel-livepatch-6.12.94-123.174Upgrade bpftool6.12Upgrade kernel6.18-tools-debuginfoUpgrade kernel6.12-debuginfo-common-x86_64Upgrade bpftool6.18-debuginfoUpgrade perf6.18-debuginfoUpgrade kernel6.12Upgrade kernel-headersUpgrade kernel-debuginfo-common-x86_64Upgrade microvm-kernel6.18Upgrade kernel6.12-debuginfo-common-aarch64Upgrade kernel6.12-tools-develUpgrade python3-perf6.18-debuginfoUpgrade kernel6.18-modules-extraUpgrade kernel6.12-modules-extra-commonUpgrade kernel6.12-debuginfoUpgrade kernel-modules-extraUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel-livepatch-6.18.36-69.134Upgrade bpftool-debuginfoUpgrade kernel6.12-modules-extraUpgrade bpftool6.12-debuginfoUpgrade perf6.12Upgrade perf-debuginfoUpgrade kernel6.18-debuginfoUpgrade kernel6.12-tools | Jul 8, 2026 | Jun 25, 2026 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Jul 5, 2026 | Jul 5, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade linux-image-nvidia-7.0Upgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-gke-64kUpgrade linux-image-7.0.0-1012-awsUpgrade linux-image-oracle-7.0Upgrade linux-image-genericUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-7.0.0-1018-nvidiaUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-virtual-hwe-26.04Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-31-realtimeUpgrade linux-image-7.0.0-2018-nvidia-bos-64kUpgrade linux-image-ibmUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-aws-64k-7.0Upgrade linux-image-raspiUpgrade linux-image-azure-lts-26.04Upgrade linux-image-7.0.0-1018-nvidia-64kUpgrade linux-image-nvidia-bosUpgrade linux-image-gke-7.0Upgrade linux-image-realtime-hwe-26.04Upgrade linux-image-oem-26.04Upgrade linux-image-oem-7.0Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-ibm-7.0Upgrade linux-image-nvidia-64k-7.0Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-7.0.0-1012-aws-64kUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-generic-64kUpgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-31-realtime-64kUpgrade linux-image-gke-64k-7.0Upgrade linux-image-7.0.0-2018-nvidia-bosUpgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-oem-26.04aUpgrade linux-image-azureUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-azure-7.0Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-gcp-64k-7.0Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-virtualUpgrade linux-image-realtimeUpgrade linux-image-oracleUpgrade linux-image-oem-26.04bUpgrade linux-image-raspi-realtimeUpgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-1019-raspiUpgrade linux-image-generic-64k-7.0Upgrade linux-image-7.0.0-1013-oemUpgrade linux-image-virtual-7.0Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-realtime-64kUpgrade linux-image-oracle-64kUpgrade linux-image-aws-64kUpgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-aws-7.0Upgrade linux-image-gkeUpgrade linux-image-7.0.0-1013-ibmUpgrade linux-image-realtime-7.0Upgrade linux-image-generic-hwe-26.04Upgrade linux-image-7.0.0-31-generic-64kUpgrade linux-image-7.0.0-1019-raspi-realtimeUpgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-awsUpgrade linux-image-7.0.0-31-genericUpgrade linux-image-raspi-7.0Upgrade linux-image-oracle-64k-7.0Upgrade linux-image-gke-hwe-26.04Upgrade linux-image-gke-64k-hwe-26.04Upgrade linux-image-gcpUpgrade linux-image-7.0.0-1014-azureUpgrade linux-image-7.0.0-1006-gke-64kUpgrade linux-image-7.0.0-1006-gkeUpgrade linux-image-virtual-hwe-24.04 | Sep 14, 2026 | Sep 7, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 6, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub