KernelScan.io

HIGH Introduced in 2.6.12

net SocketStamp UAF

CVE-2026-98276

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.0HIGH

01

In the Linux kernel, the following vulnerability has been resolved: net: lock the socket in sock_gettstamp() sk->sk_flags must only be changed while holding the socket lock, because sock_set_flag() and sock_reset_flag() use non atomic operations (__set_bit() and __clear_bit()). sock_gettstamp() is one of the last places where a bit of sk->sk_flags is changed from a syscall without owning the socket lock, through sock_enable_timestamp(sk, SOCK_TIMESTAMP). sk_set_memalloc() and sk_clear_memalloc() also change sk->sk_flags without the socket lock, but their callers (nbd, iscsi_tcp, nvme-tcp, sunrpc, wireguard) need a careful audit, this will be addressed in a separate patch. Jungwoo Lee and Wongi Lee reported an UDP socket use-after-free caused by this bug: a SIOCGSTAMPNS_NEW ioctl racing with bind() can cancel the SOCK_RCU_FREE bit that udp_lib_get_port() just set, because both threads perform a read-modify-write on the same word. CPU 0 (bind) CPU 1 (SIOCGSTAMPNS_NEW) -------------------------------- ---------------------------- read sk_flags = F read sk_flags = F compute F | BIT(SOCK_RCU_FREE) compute F | BIT(SOCK_TIMESTAMP) store F | BIT(SOCK_RCU_FREE) sk_add_node_rcu(sk, ...) store F | BIT(SOCK_TIMESTAMP) After the lost update, SOCK_RCU_FREE is clear while the socket is visible to lockless UDP receive lookups. sk_destruct() then frees the socket immediately instead of waiting for a RCU grace period, while the receive path still holds a reference-less pointer to it: BUG: KASAN: slab-use-after-free in ipv4_pktinfo_prepare+0x30/0x410 Read of size 8 at addr ffff888008806610 by task exploit/207 CPU: 0 UID: 1000 PID: 207 Comm: exploit Not tainted 6.12.95+ #1 ipv4_pktinfo_prepare+0x30/0x410 udp_queue_rcv_one_skb+0x51c/0x1180 udp_unicast_rcv_skb+0x109/0x350 ip_protocol_deliver_rcu+0x14b/0x310 ip_local_deliver_finish+0x29d/0x390 ip_local_deliver+0x24d/0x2a0 Only grab the socket lock when SOCK_TIMESTAMP has to be set, to keep the common case lockless.

02

Engine v0.7.0

Risk summary

An unprivileged local user can race a timestamp ioctl against bind() on a UDP socket, causing a lost update on socket flags that clears the RCU-free protection. This leads to a use-after-free when the socket is freed while the lockless UDP receive path still holds a pointer to it, potentially allowing kernel code execution or a system crash.

Affectednet/core/sock.c (core networking)

Vulnerability analysis

A race condition exists between a timestamp retrieval ioctl and a bind() call on the same UDP socket. Both operations perform non-atomic read-modify-write updates to the socket's flag word; when the ioctl's write lands after bind's, it overwrites the RCU-free flag that bind just set. With that flag cleared, the socket is freed immediately on close instead of waiting for an RCU grace period, while the lockless UDP receive path may still be using a reference-less pointer to the socket—resulting in a use-after-free. The fix acquires the socket lock before enabling the timestamp flag, serializing the modification with other socket-lock holders while keeping the common case (timestamp already enabled) lockless. Any local unprivileged user can trigger this by creating a UDP socket and racing the two syscalls; no special capabilities, hardware, or configuration are required.

03

BranchIntroducedFixed inPatch commit
5.102.6.125.10.27118899e2e4023
5.152.6.125.15.22288c804847dd8
6.12.6.126.1.1893b12d3967e96
6.62.6.126.6.15817b2a1eb97fd
6.122.6.126.12.1121f73253add83
6.182.6.126.18.54d9f96bc2d822
7.22.6.127.2.8899650bbf985
mainline2.6.127.3-rc49ed55f3dbef4