CVE-2026-74628
In the Linux kernel, the following vulnerability has been resolved:
net/x25: fix use-after-free of the socket by its timers
The x25 timers are armed with mod_timer() and cancelled with
timer_delete(), so a pending timer holds no reference on the socket and a
cancel does not wait for a callback already running on another CPU.
x25heartbeatexpiry() also rearms unconditionally, so it can reinstall
sk->sktimer after x25destroy_socket() has passed its cancel point.
The following _sockput() frees the socket while the timer is still
queued, and the next expiry uses freed memory. KASAN reports a
slab-use-after-free on the kmalloc-2k object freed by close().
timerdeletesync() cannot be used here: x25heartbeatexpiry() and
x25timerexpiry() both reach the cancels from inside the timer they
would wait on, through _x25destroysocket() and x25disconnect().
Arm the timers with skresettimer() and cancel them with skstoptimer()
so that an armed timer owns a reference, and release it in both expiry
handlers. Rearm the heartbeat only while sk_hashed(sk) is still true,
since _x25destroy_socket() unlinks the socket before dropping it. Arm
the deferred destroy timer the same way and drop its reference in
x25destroytimer().
Reproduced on net with KASAN, with the heartbeat period shortened so the
window recurs. With this patch the reproducer no longer triggers a
report and /proc/net/x25 drains.
Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1fc9f6d2c7c9fdb341bfe8ca449c990632299ea6, https://git.kernel.org/stable/c/2195424c3da2ef1829a63b807e3a900a90e57d85, https://git.kernel.org/stable/c/3c4919be5d910db4beebca420953858606fba7d8, https://git.kernel.org/stable/c/4bc522b33438fefc3272840ae5988771863a4f1f, https://git.kernel.org/stable/c/6b79659590f0f82a9b8efd2ffd55ec6399ebfc33, https://git.kernel.org/stable/c/ba925a2e98ce967a0e71c5bcbcf5dbd3facaf0c8, https://git.kernel.org/stable/c/e92c7e2b41d1528a830bc64c5e4e46dfa8133dda, https://git.kernel.org/stable/c/fdd9ac50b9b61ef2b2d52c5156aff788be91454d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74628.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74628, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git