CVE-2026-98374: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix use-after-free of retransmitskbhint in tcpsendsynack()
When tcpsendsynack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcprtxqueueunlinkandfree() and only repairs tp->highestsack. tp->retransmitskbhint keeps pointing at the freed skbufffclonecache object.
The dangling hint is read in tcpverifyretransmithint() and used as the root of the rbtree walk in tcpxmitretransmitqueue(). An unprivileged TFO client (sendmsg(MSGFASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb:
BUG: KASAN: slab-use-after-free in tcpmarkskblost (net/ipv4/tcpinput.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcpmarkskblost (net/ipv4/tcpinput.c:1316) tcpsimpleretransmit (net/ipv4/tcpinput.c:3158) tcpv4err (net/ipv4/tcpipv4.c:587)
Sync the hint to the copy.
Affected Software
Event History
Frequently Asked Questions
What conditions are needed to trigger the issue?
An unprivileged client must use TCP Fast Open via sendmsg(MSG_FASTOPEN) and arm the retransmit hint with an attacker-supplied ICMP fragmentation-needed message. A simultaneous open must then cause the armed SYN skb to be freed.
How might an affected system present the problem?
The supplied failure example is a KASAN slab-use-after-free report in tcp_mark_skb_lost, reached through tcp_simple_retransmit and tcp_v4_err. The invalid read occurs after retransmit_skb_hint continues to reference a freed skbuff object.