Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-74628

net/x25: fix use-after-free of the socket by its timers
Back to all
CVE

CVE-2026-74628

net/x25: fix use-after-free of the socket by its timers

In the Linux kernel, the following vulnerability has been resolved:

net/x25: fix use-after-free of the socket by its timers

The x25 timers are armed with mod_timer() and cancelled with

timer_delete(), so a pending timer holds no reference on the socket and a

cancel does not wait for a callback already running on another CPU.

x25heartbeatexpiry() also rearms unconditionally, so it can reinstall

sk->sktimer after x25destroy_socket() has passed its cancel point.

The following _sockput() frees the socket while the timer is still

queued, and the next expiry uses freed memory.  KASAN reports a

slab-use-after-free on the kmalloc-2k object freed by close().

timerdeletesync() cannot be used here: x25heartbeatexpiry() and

x25timerexpiry() both reach the cancels from inside the timer they

would wait on, through _x25destroysocket() and x25disconnect().

Arm the timers with skresettimer() and cancel them with skstoptimer()

so that an armed timer owns a reference, and release it in both expiry

handlers.  Rearm the heartbeat only while sk_hashed(sk) is still true,

since _x25destroy_socket() unlinks the socket before dropping it.  Arm

the deferred destroy timer the same way and drop its reference in

x25destroytimer().

Reproduced on net with KASAN, with the heartbeat period shortened so the

window recurs.  With this patch the reproducer no longer triggers a

report and /proc/net/x25 drains.

Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6, https://git.kernel.org/stable/c/2195424c3da2ef1829a63b807e3a900a90e57d85, https://git.kernel.org/stable/c/3c4919be5d910db4beebca420953858606fba7d8, https://git.kernel.org/stable/c/4bc522b33438fefc3272840ae5988771863a4f1f, https://git.kernel.org/stable/c/6b79659590f0f82a9b8efd2ffd55ec6399ebfc33, https://git.kernel.org/stable/c/ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8, https://git.kernel.org/stable/c/e92c7e2b41d1528a830bc64c5e4e46dfa8133dda, https://git.kernel.org/stable/c/fdd9ac50b9b61ef2b2d52c5156aff788be91454d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74628.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74628, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00734%
EPSS Percentile
0.52568%
Introduced Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2,2.6.12,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
2195424c3da2ef1829a63b807e3a900a90e57d85,5.10.267,5.15.217,6.1.184,6.6.153,6.12.105,6.18.45,7.1.9,6.1.187-1,6.12.107-1~deb12u1,6.12.105-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading