← All Advisories

Linux Kernel TIPC Socket Creation Error Path Frees the sk While Leaving sock->sk Pointing at the Freed Object, Enabling a Use-After-Free on Subsequent Socket Operations

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-68117

Key Details

CVECVE-2026-68117
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-08-19
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.

What to Know

In the Linux kernel, the following vulnerability has been resolved:

tipc: clear sock->sk on the failed-insert path in tipc_sk_create()

When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()

returns non-zero), its error path frees the sk with sk_free() but leaves

sock->sk pointing at the freed object:

if (tipc_sk_insert(tsk)) {

sk_free(sk);

pr_warn("Socket create failed; port number exhausted\n");

return -EINVAL;

}

This is harmless for plain socket(): the syscall layer clears sock->ops

before releasing, so tipc_release() is never called. It is not harmless

on the accept() path. tipc_accept() creates the pre-allocated child

socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves

new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then

fput()s the new file, so __sock_release() -> tipc_release() runs

lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the

sk_lock spinlock.

tipc_release() already guards this exact "failed accept() releases a

pre-allocated child" case with "if (sk == NULL) return 0;", but the

guard is bypassed because tipc_sk_create() left sock->sk non-NULL

(dangling) rather than NULL.

Clear sock->sk on the failed-insert path so the existing tipc_release()

NULL check fires and the use-after-free is avoided.

The tipc_sk_insert() failure is reached when the per-netns socket

rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M

elements) -- i.e. once a netns holds ~2M TIPC sockets every insert

returns -E2BIG.

BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839)

Write of size 8 at addr ffff8880047cdc38 by task init/1

lock_sock_nested (net/core/sock.c:3839)

tipc_release (net/tipc/socket.c:638)

__sock_release (net/socket.c:710)

sock_close (net/socket.c:1501)

__fput (fs/file_table.c:512)

Allocated by task 1:

sk_alloc (net/core/sock.c:2308)

tipc_sk_create (net/tipc/socket.c:487)

tipc_accept (net/tipc/socket.c:2744)

do_accept (net/socket.c:2034)

Freed by task 1:

__sk_destruct (net/core/sock.c:2391)

tipc_sk_create (net/tipc/socket.c:504)

tipc_accept (net/tipc/socket.c:2744)

do_accept (net/socket.c:2034) (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68117
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68117