Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-53260

tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().
Back to all
CVE

CVE-2026-53260

tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().

In the Linux kernel, the following vulnerability has been resolved:

tcp: Add preempt{disable,enable}nested() in reqskqueuehash_req().

syzbot reported a weird reqsk->rsk_refcnt underflow in

_inetcskreqskqueue_drop().

The captured reqskput() in inetcskreqskqueue_drop()

is called only when it successfully removes reqsk from ehash.

Moreover, reqsktimerhandler() calls another reqsk_put()

after that.

This indicates that the reqsk was missing both refcnts for

ehash and the timer itself.

Since all the syzbot reports had PREEMPT_RT enabled, the only

possible scenario is that reqskqueuehash_req() is preempted

after modtimer() and before refcountset(), and then the timer

triggered after 1s aborts the reqsk due to its listener's close().

Let's wrap modtimer() and refcountset() with

preemptdisablenested() and preemptenablenested().

Note that inetehashinsert() holds the normal spin_lock()

(mutex in PREEMPT_RT), so it must be called outside of

preemptdisablenested(), but this is fine.

The lookup path just ignores 0 sk_refcnt entries in ehash

and tries to create another reqsk, but this will fail at

inetehashinsert().

[0]:

refcount_t: underflow; use-after-free.

WARNING: lib/refcount.c:28 at refcountwarnsaturate+0xb2/0x110 lib/refcount.c:28, CPU#0: ktimers/0/16

Modules linked in:

CPU: 0 UID: 0 PID: 16 Comm: ktimers/0 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)}

Tainted: [L]=SOFTLOCKUP

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026

RIP: 0010:refcountwarnsaturate+0xb2/0x110 lib/refcount.c:28

Code: e4 7d d1 0a 67 48 0f b9 3a eb 4a e8 38 3d 23 fd 48 8d 3d e1 7d d1 0a 67 48 0f b9 3a eb 37 e8 25 3d 23 fd 48 8d 3d de 7d d1 0a <67> 48 0f b9 3a eb 24 e8 12 3d 23 fd 48 8d 3d db 7d d1 0a 67 48 0f

RSP: 0000:ffffc90000157948 EFLAGS: 00010246

RAX: ffffffff84a1301b RBX: 0000000000000003 RCX: ffff88801ca98000

RDX: 0000000000000100 RSI: 0000000000000000 RDI: ffffffff8f72ae00

RBP: ffffffff99ae3b01 R08: ffff88801ca98000 R09: 0000000000000005

R10: 0000000000000100 R11: 0000000000000004 R12: ffff8880425ef568

R13: ffff8880425ef4f8 R14: ffff8880425ef578 R15: 0000000000000000

FS:  0000000000000000(0000) GS:ffff888126386000(0000) knlGS:0000000000000000

CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 00007f7b46710e9c CR3: 000000000dbb6000 CR4: 00000000003526f0

Call Trace:

 <TASK>

 _refcountsubandtest include/linux/refcount.h:400 [inline]

 _refcountdecandtest include/linux/refcount.h:432 [inline]

 refcountdecand_test include/linux/refcount.h:450 [inline]

 reqskput include/net/requestsock.h:136 [inline]

 _inetcskreqskqueuedrop+0x3ce/0x440 net/ipv4/inetconnection_sock.c:1007

 reqsktimerhandler+0x651/0xdf0 net/ipv4/inetconnectionsock.c:1137

 calltimerfn+0x192/0x5e0 kernel/time/timer.c:1748

 expire_timers kernel/time/timer.c:1799 [inline]

 _runtimers kernel/time/timer.c:2374 [inline]

 _runtimer_base+0x6a3/0x9f0 kernel/time/timer.c:2386

 runtimerbase kernel/time/timer.c:2395 [inline]

 runtimersoftirq+0x67/0x170 kernel/time/timer.c:2403

 handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622

 _dosoftirq kernel/softirq.c:656 [inline]

 run_ktimerd+0x69/0x100 kernel/softirq.c:1151

 smpbootthreadfn+0x541/0xa50 kernel/smpboot.c:160

 kthread+0x388/0x470 kernel/kthread.c:436

 retfromfork+0x514/0xb70 arch/x86/kernel/process.c:158

 retfromforkasm+0x1a/0x30 arch/x86/entry/entry64.S:245

 </TASK>

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/889fc99967007e2493833515a645cb2d800f6742, https://git.kernel.org/stable/c/b183215ff714efb747d9d5a429322ba6404b5401, https://git.kernel.org/stable/c/de5a46f3b2c8d3cd20afa158bd3a725e3e3d6fd3, https://git.kernel.org/stable/c/e10902df24488ca722303133acfc82490f7d59ad, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53260.json, https://nvd.nist.gov/vuln/detail/CVE-2026-53260, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00369%
EPSS Percentile
0.29758%
Introduced Version
d2d6422f8bd17c6bb205133e290625a564194496,6.12.0,6.13.0,6.19.0,0
Fix Available
e10902df24488ca722303133acfc82490f7d59ad,6.12.97,6.18.40,7.0.13,6.12.100-1~deb12u1,6.12.100-1,6.18.38-r2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading