{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80738","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.789Z","datePublished":"2026-09-03T08:21:53.143Z","dateUpdated":"2026-09-04T04:58:23.870Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T04:58:23.870Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in bpf_tcp_gen_syncookie/bpf_tcp_check_syncookie BPF helpers invoked only from locally loaded and attached TC clsact or XDP programs via bpf(); per kernel CNA guidance BPF/tc paths are Local even when later triggered by ingress packets.\nAC:L - An attacker who loads the BPF program fully controls passing bpf_skc_lookup_tcp() results (request_sock/TCP_NEW_SYN_RECV or timewait sockets) into the syncookie helpers and can reliably trigger the bad sk_protocol read with crafted SYN/ACK traffic; no uncontrollable races or rare layout are required.\nPR:L - Exploitation requires bpf(BPF_PROG_LOAD) (CAP_BPF, obtainable in user namespaces) plus attaching TC/XDP hooks (CAP_NET_ADMIN via unshare -Urn); no init-namespace root is needed, matching CNA guidance for namespace-reachable net/BPF capabilities.\nUI:N - No victim mount, login, or cooperative action is required; once the attacker loads and attaches their BPF program, sending network packets from their own processes deterministically reaches the vulnerable helper on each matching lookup.\nS:U - Impact is confined to kernel heap disclosure/type confusion within the host kernel security domain; it does not cross VM, container runtime, IOMMU, or other security-authority boundaries.\nC:H - Casting a mini-socket to struct sock and reading sk_protocol performs a fixed-offset out-of-bounds read (~300+ bytes past request_sock/inet_timewait_sock) into adjacent slab memory, leaking kernel heap contents including pointers usable for further local exploitation.\nI:H - This is type confusion between ARG_PTR_TO_BTF_ID_SOCK_COMMON mini-sockets and full struct sock fields; per CNA guidance type confusion is rated High integrity impact even though the immediate bug is a read, because mis-typed socket pointers corrupt the kernel's object model.\nA:L - The primary impact is information disclosure; while the out-of-bounds u16 read usually stays within the slab page, reads near allocation boundaries or under KASAN can fault and oops the kernel, giving at least Low availability impact when uncertain."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/filter.c"],"versions":[{"version":"399040847084a69f345e0a52fd62f04654e0fce3","lessThan":"23f682083aa3fbc0c49667818efd6979a8bc5ac2","status":"affected","versionType":"git"},{"version":"399040847084a69f345e0a52fd62f04654e0fce3","lessThan":"31a420a822ff92e2090bd5d65efe8e34e2d6d9b8","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/filter.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"7.1.9","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/23f682083aa3fbc0c49667818efd6979a8bc5ac2"},{"url":"https://git.kernel.org/stable/c/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8"}],"title":"bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie","x_generator":{"engine":"bippy-1.2.0"}}}}