{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.101-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()  tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock.  Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock-\u003ecork.  This comparison is unsafe when two threads send on the same socket:    Thread A                         Thread B   msg_tx = psock-\u003ecork   sk_msg_alloc() fails   sk_stream_wait_memory()     releases the socket lock      acquires the socket lock                                   completes the cork                                   psock-\u003ecork = NULL                                   frees the cork     reacquires the socket lock   msg_tx != psock-\u003ecork   sk_msg_free(msg_tx)  The stale cork is therefore mistaken for the local temporary message and freed again.  KASAN reported:    BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50   Read of size 4 at addr ffff88810c908800 by task poc/90   Call Trace:    sk_msg_free+0x49/0x50    tcp_bpf_sendmsg+0x14f5/0x1cc0    __sys_sendto+0x32c/0x3a0    __x64_sys_sendto+0xdb/0x1b0   Allocated by task 89:    __kasan_kmalloc+0x8f/0xa0    tcp_bpf_sendmsg+0x16b3/0x1cc0   Freed by task 91:    __kasan_slab_free+0x43/0x70    kfree+0x131/0x3c0    tcp_bpf_sendmsg+0xec3/0x1cc0  msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock-\u003ecork cannot turn a shared message into an apparent local one.",
  "id": "DEBIAN-CVE-2026-68284",
  "modified": "2026-09-14T16:47:30.041850157Z",
  "published": "2026-08-10T13:20:17.670Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-68284"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-68284"
  ]
}