CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix UAF in sock clone early bailouts

Similar to recent commit 9b51a6155d14 ("bpf,fork: wipe ->bpfstorage before bailouts that access it"), skclone() performs an initial shallow copy of the socket field ->skbpfstorage via sockcopy() for the cloned socket newsk.

If skclone() bails out early (e.g. if skfiltercharge() fails) prior to calling bpfskstorageclone(), newsk->skbpfstorage still points to the parent socket's BPF local storage. When newsk is subsequently freed via skfree(), the deallocation path (skdestruct() -> bpfskstoragefree()) destroys the parent socket's BPF local storage, leading to a use-after-free (UAF) on the parent socket.

Fix this by resetting newsk->skbpfstorage to NULL immediately after sockcopy() in skclone(), and remove the now redundant initialization from bpfskstorageclone().

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Reset newsk->sk_bpf_storage to NULL immediately after the initial shallow copy via sock_copy() in sk_clone, so early bailouts that call bpf_sk_storage_clone()/bpf_sk_storage_free() do not leave newsk->sk_bpf_storage pointing to the parent socket's BPF local storage.

    Linux kernel (BPF sock clone path / sk_clone) newsk->sk_bpf_storage = NULL

Event History

Aug 10, 2026
CVE Published
via MITRE·12:04 PM
Data Sourced
via MITRE·12:04 PM
Description
Data Sourced
via NVD·01:20 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68399?

CVE-2026-68399 has a risk rating of 47, indicating a potential security threat.

2

What type of vulnerability is CVE-2026-68399?

CVE-2026-68399 is classified as a Use After Free vulnerability.

3

How do I fix CVE-2026-68399?

To fix CVE-2026-68399, update to the latest version of the Linux kernel where the vulnerability has been resolved.

4

What component is affected by CVE-2026-68399?

CVE-2026-68399 affects the BPF (Berkeley Packet Filter) implementation in the Linux kernel.

5

When was CVE-2026-68399 published?

CVE-2026-68399 was published on August 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203