Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98374— tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: tcp: 修复 tcp_send_synack() 中对 retransmit_skb_hint 的释放后使用(use-after-free)问题 当 用其副本替换重传队列头部克隆的 SYN 报文(skb)时,它会通过 释放原始 skb,但仅修复了 。此时, 仍然指向已释放的 对象。 该悬空指针(dangling hint)会在 中被读取,并作为 中红黑树遍历的起点。非特权的 TCP 快速打开(TFO)客户端(通过 )可以利用攻击者提供的 ICMP “需要分片”(fragm

AI Predicted 7.8 Difficulty: Moderate

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux c31b70c9968fe9c4194d1b5d06d07596a3b680de< fad6d429651e748365e93ca54645accc212f0018 affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< c5b4da1f403a658c1c19766be2b426003ada419f affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 71d45049b0d631dfdbf3c65305f7fca676de023b affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< e3ea71cb1408a013ed4e8a757b815f1a919324bd affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 631aa4cb45099f09e9385dd786bd291c6270bfc4 affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< 0f87720c7e4bcab07c24888b3cf12bfe857bb90e affected
c31b70c9968fe9c4194d1b5d06d07596a3b680de< fe99bbeee5c5dbd3abc30721a8079ced59649d97 affected
5.11 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98374

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_unlink_and_free() and only repairs tp->highest_sack. tp->retransmit_skb_hint keeps pointing at the freed skbuff_fclone_cache object. The dangling hint is read in tcp_verify_retransmit_hint() and used as the root of the rbtree walk in tcp_xmit_retransmit_queue(). An unprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb: BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316) tcp_simple_retransmit (net/ipv4/tcp_input.c:3158) tcp_v4_err (net/ipv4/tcp_ipv4.c:587) Sync the hint to the copy.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c31b70c9968fe9c4194d1b5d06d07596a3b680de ~ fad6d429651e748365e93ca54645accc212f0018 -
Linux Linux 5.11 -

II. Public POCs for CVE-2026-98374

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98374

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98374 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-98374

No comments yet


Leave a comment