{"api_version":"1","generated_at":"2026-09-06T16:32:52+00:00","cve":"CVE-2026-80738","urls":{"html":"https://cve.report/CVE-2026-80738","api":"https://cve.report/api/cve/CVE-2026-80738.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80738","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80738"},"summary":{"title":"bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-03 13:06:12","updated_at":"2026-09-04 05:17:14"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.3","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","data":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/23f682083aa3fbc0c49667818efd6979a8bc5ac2","name":"https://git.kernel.org/stable/c/23f682083aa3fbc0c49667818efd6979a8bc5ac2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8","name":"https://git.kernel.org/stable/c/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80738","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80738","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 399040847084a69f345e0a52fd62f04654e0fce3 23f682083aa3fbc0c49667818efd6979a8bc5ac2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 399040847084a69f345e0a52fd62f04654e0fce3 31a420a822ff92e2090bd5d65efe8e34e2d6d9b8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.9 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80738","cve":"CVE-2026-80738","epss":"0.001180000","percentile":"0.019120000","score_date":"2026-09-05","updated_at":"2026-09-06 00:04:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"23f682083aa3fbc0c49667818efd6979a8bc5ac2","status":"affected","version":"399040847084a69f345e0a52fd62f04654e0fce3","versionType":"git"},{"lessThan":"31a420a822ff92e2090bd5d65efe8e34e2d6d9b8","status":"affected","version":"399040847084a69f345e0a52fd62f04654e0fce3","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/core/filter.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.2"},{"lessThan":"5.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.9","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.9","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields."}],"metrics":[{"cvssV3_1":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in bpf_tcp_gen_syncookie/bpf_tcp_check_syncookie BPF helpers invoked only from locally loaded and attached TC clsact or XDP programs via bpf(); per kernel CNA guidance BPF/tc paths are Local even when later triggered by ingress packets.\nAC:L - An attacker who loads the BPF program fully controls passing bpf_skc_lookup_tcp() results (request_sock/TCP_NEW_SYN_RECV or timewait sockets) into the syncookie helpers and can reliably trigger the bad sk_protocol read with crafted SYN/ACK traffic; no uncontrollable races or rare layout are required.\nPR:L - Exploitation requires bpf(BPF_PROG_LOAD) (CAP_BPF, obtainable in user namespaces) plus attaching TC/XDP hooks (CAP_NET_ADMIN via unshare -Urn); no init-namespace root is needed, matching CNA guidance for namespace-reachable net/BPF capabilities.\nUI:N - No victim mount, login, or cooperative action is required; once the attacker loads and attaches their BPF program, sending network packets from their own processes deterministically reaches the vulnerable helper on each matching lookup.\nS:U - Impact is confined to kernel heap disclosure/type confusion within the host kernel security domain; it does not cross VM, container runtime, IOMMU, or other security-authority boundaries.\nC:H - Casting a mini-socket to struct sock and reading sk_protocol performs a fixed-offset out-of-bounds read (~300+ bytes past request_sock/inet_timewait_sock) into adjacent slab memory, leaking kernel heap contents including pointers usable for further local exploitation.\nI:H - This is type confusion between ARG_PTR_TO_BTF_ID_SOCK_COMMON mini-sockets and full struct sock fields; per CNA guidance type confusion is rated High integrity impact even though the immediate bug is a read, because mis-typed socket pointers corrupt the kernel's object model.\nA:L - The primary impact is information disclosure; while the out-of-bounds u16 read usually stays within the slab page, reads near allocation boundaries or under KASAN can fault and oops the kernel, giving at least Low availability impact when uncertain."}]}],"providerMetadata":{"dateUpdated":"2026-09-04T04:58:23.870Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/23f682083aa3fbc0c49667818efd6979a8bc5ac2"},{"url":"https://git.kernel.org/stable/c/31a420a822ff92e2090bd5d65efe8e34e2d6d9b8"}],"title":"bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80738","datePublished":"2026-09-03T08:21:53.143Z","dateReserved":"2026-08-26T14:34:25.789Z","dateUpdated":"2026-09-04T04:58:23.870Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-03 13:06:12","lastModifiedDate":"2026-09-04 05:17:14","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":5.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80738","Ordinal":"1","Title":"bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie","CVE":"CVE-2026-80738","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80738","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie\n\nbpf_tcp_gen_syncookie and bpf_tcp_check_syncookie accept a socket pointer\n'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access\nsk->sk_protocol without validating whether 'sk' represents a full socket.\n\nFix this issue by checking sk->sk_state != TCP_LISTEN before inspecting\nsk->sk_protocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie.\nSince mini-sockets are never in the TCP_LISTEN state, the condition\nshort-circuits and prevents dereferencing fullsock-specific fields.","Type":"Description","Title":"bpf: Check sk_state before sk_protocol in bpf_tcp_*_syncookie"}]}}}