Skip to main content
Vulnerability Database/CVE-2026-98374

CVE-2026-98374: Linux Kernel TCP Use-After-Free Vulnerability

CVE-2026-98374 is a use-after-free flaw in the Linux kernel TCP implementation that allows unauthorized memory access through dangling pointers. This article covers technical details, system impact, and mitigation strategies.

Published:

CVE-2026-98374 Overview

CVE-2026-98374 is a use-after-free vulnerability in the Linux kernel's TCP stack. The flaw resides in tcp_send_synack(), where the function replaces the cloned SYN skb at the head of the retransmit queue with a copy. The original skb is freed through tcp_rtx_queue_unlink_and_free(), but tp->retransmit_skb_hint continues to reference the freed skbuff_fclone_cache object. An unprivileged TCP Fast Open (TFO) client can arm the dangling hint using a crafted ICMP fragmentation-needed message, then trigger the free through a simultaneous open, resulting in memory corruption inside the kernel network stack.

Critical Impact

An unprivileged local or network-adjacent attacker can trigger a kernel use-after-free in the TCP code path, enabling denial of service and potentially kernel memory corruption.

Affected Products

  • Linux kernel versions containing the vulnerable tcp_send_synack() logic prior to the fix commits
  • Linux distributions shipping affected stable kernel branches
  • Systems with TCP Fast Open (TFO) enabled for client sockets

Discovery Timeline

  • 2026-10-07 - CVE-2026-98374 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98374

Vulnerability Analysis

The vulnerability is a use-after-free [CWE-416] in the Linux kernel TCP output path. When tcp_send_synack() needs to retransmit a SYN-ACK, it swaps the cloned SYN skb at the head of the retransmit queue with a freshly allocated copy. The original buffer is released via tcp_rtx_queue_unlink_and_free().

The function updates tp->highest_sack to reflect the new buffer but does not update tp->retransmit_skb_hint. That pointer still references the freed skbuff_fclone_cache entry. Subsequent code paths dereference the stale hint during retransmission walks, reading freed slab memory.

Root Cause

The root cause is incomplete pointer bookkeeping after an skb replacement. tp->retransmit_skb_hint serves as a cached starting point for the rbtree walk in tcp_xmit_retransmit_queue() and is validated by tcp_verify_retransmit_hint(). Because tcp_send_synack() only repairs tp->highest_sack, the hint continues to point at freed memory. The fix synchronizes the hint to the replacement skb whenever the head of the retransmit queue is swapped.

Attack Vector

An unprivileged TCP Fast Open client issuing sendmsg(MSG_FASTOPEN) can arm the dangling hint by delivering an attacker-controlled ICMP fragmentation-needed message. A simultaneous open then frees the armed SYN skb, and the next call into tcp_simple_retransmit() from tcp_v4_err() dereferences the stale pointer. KASAN confirms the condition:

BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
Read of size 4 at addr ffff88800604d928 by task swapper/1/0
Call Trace:
tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)
tcp_simple_retransmit (net/ipv4/tcp_input.c:3158)
tcp_v4_err (net/ipv4/tcp_ipv4.c:587)

See the upstream fix in Linux Kernel Commit 0f87720c for the exact code change.

Detection Methods for CVE-2026-98374

Indicators of Compromise

  • Kernel KASAN or slab-use-after-free reports naming tcp_mark_skb_lost, tcp_simple_retransmit, or tcp_v4_err in the call trace.
  • Unexpected kernel panics or oopses on hosts handling inbound ICMP fragmentation-needed messages combined with TFO traffic.
  • Anomalous volumes of ICMP type 3 code 4 (fragmentation needed) messages targeting hosts that accept TFO connections.

Detection Strategies

  • Enable KASAN on test and staging kernels to catch slab use-after-free conditions in the TCP output path.
  • Monitor kernel ring buffer (dmesg) and syslog for TCP-related oops traces referencing retransmit or SYN-ACK handling.
  • Correlate ICMP unreachable traffic with TCP Fast Open socket activity to identify suspicious patterns.

Monitoring Recommendations

  • Ship /var/log/kern.log and dmesg output to a centralized logging platform and alert on KASAN or BUG: entries.
  • Track crash frequency and kernel.panic counters across fleets to detect regressions tied to TCP paths.
  • Audit sysctl values such as net.ipv4.tcp_fastopen to understand exposure across hosts.

How to Mitigate CVE-2026-98374

Immediate Actions Required

  • Apply the upstream Linux kernel patches that synchronize tp->retransmit_skb_hint with the replacement skb in tcp_send_synack().
  • Prioritize patching of internet-facing hosts and gateways that terminate TCP connections and accept ICMP messages.
  • Reboot into the patched kernel after installation to ensure the vulnerable code path is replaced in memory.

Patch Information

The vulnerability is corrected across multiple stable branches. Reference the following commits: Linux Kernel Commit 0f87720c, Linux Kernel Commit 631aa4cb, Linux Kernel Commit 71d45049, Linux Kernel Commit c5b4da1f, Linux Kernel Commit e3ea71cb, Linux Kernel Commit fad6d429, and Linux Kernel Commit fe99bbee.

Workarounds

  • Disable TCP Fast Open on client sockets where it is not required by setting net.ipv4.tcp_fastopen to 0.
  • Rate limit or filter inbound ICMP type 3 code 4 (fragmentation needed) messages at perimeter firewalls where PMTU discovery is not required.
  • Restrict untrusted local users on multi-tenant hosts until the patched kernel is deployed.
bash
# Disable TCP Fast Open client mode as a temporary mitigation
sysctl -w net.ipv4.tcp_fastopen=0
echo 'net.ipv4.tcp_fastopen = 0' > /etc/sysctl.d/99-cve-2026-98374.conf
sysctl --system

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.