HIGH Introduced in 5.2
bpf SockClone UAF
CVE-2026-68399
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in sock clone early bailouts Similar to recent commit 9b51a6155d14 ("bpf,fork: wipe ->bpf_storage before bailouts that access it"), sk_clone() performs an initial shallow copy of the socket field ->sk_bpf_storage via sock_copy() for the cloned socket newsk. If sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior to calling bpf_sk_storage_clone(), newsk->sk_bpf_storage still points to the parent socket's BPF local storage. When newsk is subsequently freed via sk_free(), the deallocation path (__sk_destruct() -> bpf_sk_storage_free()) destroys the parent socket's BPF local storage, leading to a use-after-free (UAF) on the parent socket. Fix this by resetting newsk->sk_bpf_storage to NULL immediately after sock_copy() in sk_clone(), and remove the now redundant initialization from bpf_sk_storage_clone().
02KernelScan AI Analysis
Risk summary
A local attacker can trigger a use-after-free on a parent socket's BPF local storage by inducing an early bailout during socket cloning. The freed storage remains referenced by the parent socket, enabling heap corruption that can lead to kernel code execution or a system crash. Any system using BPF socket local storage (e.g., Cilium, system observability tools) is at risk.
Vulnerability analysis
When a socket is cloned, the kernel performs a shallow copy that includes the parent socket's BPF local storage pointer. If the clone operation bails out early before the BPF storage is properly initialized for the new socket, the new socket still holds a dangling reference to the parent's storage. When the failed clone is cleaned up, the parent's BPF local storage is destroyed, leaving the parent socket with a use-after-free. The fix resets the cloned socket's BPF storage pointer to NULL immediately after the shallow copy, so any early bailout path cannot accidentally free the parent's storage. This is reachable by any local user who can trigger socket cloning (such as through incoming connections on a listening socket), provided BPF local storage has been configured on the socket, which requires BPF program loading privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 5.2 | 7.2-rc4 | 7cbd0c4cebe4 |
| 7.1 | 5.2 | 7.1.6 | 14b49b5ab299 |