KernelScan.io

HIGH Introduced in 6.18

tcp TimeWait Leak

CVE-2026-68379

CVSS 7.5 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TIME_WAIT socket reference leak on PSP policy failure Release the TIME_WAIT socket reference and jump to discard_it upon PSP policy failure in both IPv4 and IPv6 receive paths. This prevents a memory leak of tcp_tw_bucket structures.

02

Engine v0.6.0

Risk summary

An unauthenticated remote attacker can send TCP packets to a host with PSP-enabled connections in TIME_WAIT state, triggering a memory leak of TIME_WAIT socket structures on every packet that fails PSP policy validation. Repeated exploitation can exhaust kernel memory and cause a system-wide denial of service. The vulnerability affects both IPv4 and IPv6 TCP receive paths.

Affectednet/ipv4/tcp_ipv4.c, net/ipv6/tcp_ipv6.c (tcp)

Vulnerability analysis

When an incoming TCP packet arrives for a connection in TIME_WAIT state, the receive path performs a PSP security policy check on the socket. If that check fails, the original code discards the packet but forgets to release the reference count held on the TIME_WAIT socket, leaking one kernel structure per failed check. An attacker who can send TCP traffic to the host can repeat this indefinitely, accumulating leaked structures until kernel memory is exhausted. The fix releases the TIME_WAIT socket reference and routes the packet to the normal discard path when the PSP policy check fails, closing the leak. This is reachable from the network by any unauthenticated sender, but only on systems where the PSP TCP feature is active and connections exist in TIME_WAIT state with PSP policy enforced.

03

BranchIntroducedFixed inPatch commit
mainline6.187.2-rc42c1931a81122
7.16.187.1.6374742a961be
6.186.186.18.42e666af5dcc90