Use-After-Free Vulnerability in Linux Kernel TCP Stack
CVE-2026-98374
What is CVE-2026-98374?
A use-after-free flaw was found within the TCP implementation of the Linux kernel in the tcp_send_synack() function. When tcp_send_synack() replaces a cloned SYN socket buffer in the retransmit queue, it frees the original without adequately updating tp->retransmit_skb_hint, leaving a pointer to the freed memory. This dangling pointer can be leveraged by an unprivileged TCP Fast Open (TFO) client to manipulate the SYN buffer. Specifically, if it receives an attacker-controlled ICMP fragmentation-needed message, this could potentially lead to a kernel crash or unauthorized access to kernel memory during TCP retransmission handling.
Affected Version(s)
Linux c31b70c9968fe9c4194d1b5d06d07596a3b680de
Linux c31b70c9968fe9c4194d1b5d06d07596a3b680de
Linux c31b70c9968fe9c4194d1b5d06d07596a3b680de < 71d45049b0d631dfdbf3c65305f7fca676de023b