{"id":"CVE-2026-74268","title":"tcp: clear sock_ops cb flags before force-closing a child socket","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clear sock_ops cb flags before force-closing a child socket\n\nA child socket inherits the listener's bpf_sock_ops_cb_flags via\nsk_clone_lock(). If its setup fails i…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 5d5389b2c37ca00da61d1407618ebe15abae0c8b","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 9f30ba9aa0270a18fdd1e6cd426c480c35f7de9d","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 71e9c53220abd7f5a45aa4d5e5b420d3479f3a4f","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 9fffa6465851a1910a6e9cb7272787dd615b26b1","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < fe23d56e9266d58ba5c380f1970118eedeee0b68","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < ce311bd2e36596f0aa2c92ca86fb3e019ac57eae","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 8874dafc9099bc49c2e5ebba030f85d276421f92","Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 990348e5bb457697c2f1f7f7b65154a3334d9d2b","Linux 4.16"],"published":"2026-08-15","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:42.864Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-74268","references":[{"url":"https://git.kernel.org/stable/c/5d5389b2c37ca00da61d1407618ebe15abae0c8b"},{"url":"https://git.kernel.org/stable/c/9f30ba9aa0270a18fdd1e6cd426c480c35f7de9d"},{"url":"https://git.kernel.org/stable/c/71e9c53220abd7f5a45aa4d5e5b420d3479f3a4f"},{"url":"https://git.kernel.org/stable/c/9fffa6465851a1910a6e9cb7272787dd615b26b1"},{"url":"https://git.kernel.org/stable/c/fe23d56e9266d58ba5c380f1970118eedeee0b68"},{"url":"https://git.kernel.org/stable/c/ce311bd2e36596f0aa2c92ca86fb3e019ac57eae"},{"url":"https://git.kernel.org/stable/c/8874dafc9099bc49c2e5ebba030f85d276421f92"},{"url":"https://git.kernel.org/stable/c/990348e5bb457697c2f1f7f7b65154a3334d9d2b"}],"tags":["cve.org"],"epss":0.00695,"epssPercentile":0.51572,"ingestedAt":"2026-09-14T15:23:07.456Z","slug":"CVE-2026-74268","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clear sock_ops cb flags before force-closing a child socket\n\nA child socket inherits the listener's bpf_sock_ops_cb_flags via\nsk_clone_lock(). If its setup fails in tcp_v4_syn_recv_sock() /\ntcp_v6_syn_recv_sock(), the child is freed through put_and_exit, where\ninet_csk_prepare_forced_close() drops the socket lock and tcp_done() runs\nwithout it.\n\nIf BPF_SOCK_OPS_STATE_CB_FLAG was inherited, tcp_done() -> tcp_set_state()\ncalls tcp_call_bpf(), which expects the lock and trips sock_owned_by_me():\n\n  WARNING: include/net/sock.h:1799 at tcp_set_state+0x433/0x550\n  RIP: 0010:tcp_set_state+0x433/0x550 include/net/sock.h:1799\n  Call Trace:\n   <IRQ>\n   tcp_done+0xba/0x250 net/ipv4/tcp.c:5095\n   tcp_v4_syn_recv_sock+0x850/0xa50 net/ipv4/tcp_ipv4.c:1787\n   tcp_check_req+0xf30/0x1360 net/ipv4/tcp_minisocks.c:926\n   tcp_v4_rcv+0x1047/0x1b50 net/ipv4/tcp_ipv4.c:2164\n   </IRQ>\n\nThe child is freed before it is ever established, so it should run no\nsock_ops callback. Clear its cb flags in inet_csk_prepare_for_destroy_sock(),\nthe common point for the IPv4, IPv6 and chtls forced-close paths and for the\nMPTCP ->syn_recv_sock() failure path (dispose_child), which reaches tcp_done()\non a child that was never established too.\n\n## Affected\n\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 5d5389b2c37ca00da61d1407618ebe15abae0c8b`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 9f30ba9aa0270a18fdd1e6cd426c480c35f7de9d`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 71e9c53220abd7f5a45aa4d5e5b420d3479f3a4f`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 9fffa6465851a1910a6e9cb7272787dd615b26b1`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < fe23d56e9266d58ba5c380f1970118eedeee0b68`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < ce311bd2e36596f0aa2c92ca86fb3e019ac57eae`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 8874dafc9099bc49c2e5ebba030f85d276421f92`\n- `Linux >= d44874910a26f3a8f81edf873a2473363f07f660 < 990348e5bb457697c2f1f7f7b65154a3334d9d2b`\n- `Linux 4.16`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}