Vulnerability in Linux Kernel Affecting BPF and Sockmap Functionality
CVE-2026-68386
What is CVE-2026-68386?
A vulnerability in the Linux kernel allows unbound UDP sockets to be mishandled during sockmap updates. When these sockets are auto-bound, they remain in a state where the reference count is not properly decremented, leading to potential memory leaks. The issue arises from the ability of a BPF program to manipulate socket reference counts, which can result in unbound sockets not being correctly managed upon transition to a bound state. This oversight requires rejection of unhashed UDP sockets in sockmap updates to prevent memory management issues.
Affected Version(s)
Linux 0c48eefae712c2fd91480346a07a1a9cd0f9470b < 7ffe529e7127411806c8692fb1490f552c629dc2
Linux 0c48eefae712c2fd91480346a07a1a9cd0f9470b < 17b7ef6b86112a4e61cee1e9009a4b318e3225c5
Linux 0c48eefae712c2fd91480346a07a1a9cd0f9470b < 250474c69bc3fc48a5fc21d7c349f279caad947a