CVE-2026-98384: bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()

Published Oct 9, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix out-of-bounds read of skprotocol in bpfsockdestroy()

skprotocol lives in struct sock, not in struct sockcommon. A timewait or request sock handed to bpfsockdestroy() by the tcp iterator is neither, so reading sk->skprotocol runs past the object:

================================================================== BUG: KASAN: slab-out-of-bounds in bpfsockdestroy+0xc7/0xe0 Read of size 2 at addr ffff8881047d11b4 by task testprogs/428

Tainted: [W]=WARN Call Trace: <TASK> dumpstacklvl+0x91/0xf0 printreport+0xd1/0x630 kasanreport+0xf3/0x130 asanreportload2noabort+0x14/0x30 bpfsockdestroy+0xc7/0xe0 bpfprogc3dd61f9d9cd9f37itertcp6timewait+0x9f/0xb7 bpfiterrunprog+0x538/0xde0 bpfitertcpseqshow+0x26b/0x4b0 bpfseqread+0x424/0x1210 vfsread+0x197/0xe40 ksysread+0x119/0x240 x64sysread+0x72/0xc0 x64syscall+0x647/0x27e0 dosyscall64+0xe5/0x610 entrySYSCALL64afterhwframe+0x76/0x7e

Only check skprotocol on full socks. tcpabort() already knows how to deal with TIMEWAIT and NEWSYNRECV socks. Also fix the comment, it never matched the code.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 9, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
Description
Data Sourced
via NVD·08:16 AM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Linux kernel systems that run BPF TCP iterators and pass TIME_WAIT or NEW_SYN_RECV/request sockets through bpf_sock_destroy() are affected. The reported failure occurs when the TCP iterator handles a time-wait socket.

2

What is required to trigger the out-of-bounds read?

A BPF program using the TCP iterator must cause bpf_sock_destroy() to process a socket that is not a full struct sock, such as a TIME_WAIT or request socket. Reading sk_protocol on those socket types can access beyond the underlying object.

3

What does the fix change?

The fix limits the sk_protocol check to full sockets. TIME_WAIT and NEW_SYN_RECV sockets are instead handled by tcp_abort(), which already supports those socket types.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203