Use-After-Free Vulnerability in Linux Kernel TCP-AO Implementation
CVE-2026-80850
What is CVE-2026-80850?
A vulnerability in the TCP-AO implementation of the Linux kernel could lead to use-after-free scenarios. When TCP-AO is configured, the validation of keys associated with connected sockets does not properly manage the socket's attachment to the Virtual Routing and Forwarding (VRF) domain. This oversight allows a condition where, during a connection's establishment and VRF detachment race, an old pointer can be accessed after it has been freed. As a result, this can lead to instability and potential exploitation within the network stack, especially under high-load scenarios. The issue has been corrected to ensure consistent handling of socket memory after the validation process, preventing access to freed objects.
Affected Version(s)
Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 594ba77210a1f065832211851a2d7e14d11fcbdb
Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 70051a57786d5b23f059fbaf5c8241eca14d42ed
Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 284d7fd0eec8774bd6214921fbf525cf907c590e