{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()  When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_unlink_and_free() and only repairs tp-\u003ehighest_sack. tp-\u003eretransmit_skb_hint keeps pointing at the freed skbuff_fclone_cache object.  The dangling hint is read in tcp_verify_retransmit_hint() and used as the root of the rbtree walk in tcp_xmit_retransmit_queue().  An unprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb:    BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)   Read of size 4 at addr ffff88800604d928 by task swapper/1/0   Call Trace:    tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)    tcp_simple_retransmit (net/ipv4/tcp_input.c:3158)    tcp_v4_err (net/ipv4/tcp_ipv4.c:587)  Sync the hint to the copy.",
  "id": "DEBIAN-CVE-2026-98374",
  "modified": "2026-10-08T04:47:40.980442977Z",
  "published": "2026-10-07T13:17:23.023Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98374"
    }
  ],
  "upstream": [
    "CVE-2026-98374"
  ]
}