Out-of-Bounds Read in Linux Kernel Affecting BPF Functionality
CVE-2026-98384
What is CVE-2026-98384?
A vulnerability in the Linux kernel allows for out-of-bounds reads during the execution of the bpf_sock_destroy() function. This arises from improper handling of the sk_protocol variable within struct sock, leading to the possibility of accessing unintended memory locations. Specifically, when TCP iterators hand time_wait or request sockets to bpf_sock_destroy(), the program attempts to read the sk_protocol value, causing potential security risks and system instability. The issue has been addressed in recent kernel updates to ensure that sk_protocol is only checked on full socket objects, which mitigates the associated vulnerabilities.
Affected Version(s)
Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b < 5b4eb82475ae17d55974235c09e97044829426a8
Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b
Linux 4ddbcb886268af8d12a23e6640b39d1d9c652b1b < 91a482a81eabddebf5430cbbdf12027e1a91b767