CVE-2026-98384: bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix out-of-bounds read of skprotocol in bpfsockdestroy()
skprotocol lives in struct sock, not in struct sockcommon. A timewait or request sock handed to bpfsockdestroy() by the tcp iterator is neither, so reading sk->skprotocol runs past the object:
================================================================== BUG: KASAN: slab-out-of-bounds in bpfsockdestroy+0xc7/0xe0 Read of size 2 at addr ffff8881047d11b4 by task testprogs/428
Tainted: [W]=WARN Call Trace: <TASK> dumpstacklvl+0x91/0xf0 printreport+0xd1/0x630 kasanreport+0xf3/0x130 asanreportload2noabort+0x14/0x30 bpfsockdestroy+0xc7/0xe0 bpfprogc3dd61f9d9cd9f37itertcp6timewait+0x9f/0xb7 bpfiterrunprog+0x538/0xde0 bpfitertcpseqshow+0x26b/0x4b0 bpfseqread+0x424/0x1210 vfsread+0x197/0xe40 ksysread+0x119/0x240 x64sysread+0x72/0xc0 x64syscall+0x647/0x27e0 dosyscall64+0xe5/0x610 entrySYSCALL64afterhwframe+0x76/0x7e
Only check skprotocol on full socks. tcpabort() already knows how to deal with TIMEWAIT and NEWSYNRECV socks. Also fix the comment, it never matched the code.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Linux kernel systems that run BPF TCP iterators and pass TIME_WAIT or NEW_SYN_RECV/request sockets through bpf_sock_destroy() are affected. The reported failure occurs when the TCP iterator handles a time-wait socket.
What is required to trigger the out-of-bounds read?
A BPF program using the TCP iterator must cause bpf_sock_destroy() to process a socket that is not a full struct sock, such as a TIME_WAIT or request socket. Reading sk_protocol on those socket types can access beyond the underlying object.
What does the fix change?
The fix limits the sk_protocol check to full sockets. TIME_WAIT and NEW_SYN_RECV sockets are instead handled by tcp_abort(), which already supports those socket types.