Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-74268

In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a child socket A child socket inherits the listener's bpf_sock_ops_cb_flags via ...
Back to all
CVE

DEBIAN-CVE-2026-74268

In the Linux kernel, the following vulnerability has been resolved: tcp: clear sock_ops cb flags before force-closing a child socket A child socket inherits the listener's bpf_sock_ops_cb_flags via ...

In the Linux kernel, the following vulnerability has been resolved:  tcp: clear sockops cb flags before force-closing a child socket  A child socket inherits the listener's bpfsockopscbflags via skclonelock(). If its setup fails in tcpv4synrecvsock() / tcpv6synrecvsock(), the child is freed through putandexit, where inetcskprepareforcedclose() drops the socket lock and tcpdone() runs without it.  If BPFSOCKOPSSTATECBFLAG was inherited, tcpdone() -> tcpsetstate() calls tcpcallbpf(), which expects the lock and trips sockownedbyme():    WARNING: include/net/sock.h:1799 at tcpsetstate+0x433/0x550   RIP: 0010:tcpsetstate+0x433/0x550 include/net/sock.h:1799   Call Trace:    <IRQ>    tcpdone+0xba/0x250 net/ipv4/tcp.c:5095    tcpv4synrecvsock+0x850/0xa50 net/ipv4/tcpipv4.c:1787    tcpcheckreq+0xf30/0x1360 net/ipv4/tcpminisocks.c:926    tcpv4rcv+0x1047/0x1b50 net/ipv4/tcpipv4.c:2164    </IRQ>  The child is freed before it is ever established, so it should run no sockops callback. Clear its cb flags in inetcskpreparefordestroysock(), the common point for the IPv4, IPv6 and chtls forced-close paths and for the MPTCP ->synrecvsock() failure path (disposechild), which reaches tcp_done() on a child that was never established too.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-74268

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.1.5-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading