CVE-2026-98374: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

Published Oct 7, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

tcp: fix use-after-free of retransmitskbhint in tcpsendsynack()

When tcpsendsynack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcprtxqueueunlinkandfree() and only repairs tp->highestsack. tp->retransmitskbhint keeps pointing at the freed skbufffclonecache object.

The dangling hint is read in tcpverifyretransmithint() and used as the root of the rbtree walk in tcpxmitretransmitqueue(). An unprivileged TFO client (sendmsg(MSGFASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb:

BUG: KASAN: slab-use-after-free in tcpmarkskblost (net/ipv4/tcpinput.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcpmarkskblost (net/ipv4/tcpinput.c:1316) tcpsimpleretransmit (net/ipv4/tcpinput.c:3158) tcpv4err (net/ipv4/tcpipv4.c:587)

Sync the hint to the copy.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 7, 2026
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
Description
Data Sourced
via NVD·01:17 PM
Description

Frequently Asked Questions

1

What conditions are needed to trigger the issue?

An unprivileged client must use TCP Fast Open via sendmsg(MSG_FASTOPEN) and arm the retransmit hint with an attacker-supplied ICMP fragmentation-needed message. A simultaneous open must then cause the armed SYN skb to be freed.

2

How might an affected system present the problem?

The supplied failure example is a KASAN slab-use-after-free report in tcp_mark_skb_lost, reached through tcp_simple_retransmit and tcp_v4_err. The invalid read occurs after retransmit_skb_hint continues to reference a freed skbuff object.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203