)]}'
{
  "commit": "aff334becfdb3e9c96a3fe8628c553b0934b5b08",
  "tree": "d303e969e4bc1afbcf4e157f78be53b2c0277733",
  "parents": [
    "73ba70e3a009c2231669a01ac2ea47ad1931444a"
  ],
  "author": {
    "name": "Chengfeng Ye",
    "email": "nicoyip.dev@gmail.com",
    "time": "Fri Jul 24 18:38:56 2026 +0800"
  },
  "committer": {
    "name": "Kevin Liu",
    "email": "zhihuil@google.com",
    "time": "Mon Aug 17 15:42:12 2026 -0700"
  },
  "message": "bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()\n\n[ Upstream commit 2d66a033864e27ab8d5e44cb36f31d9d2413bee4 ]\n\ntcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which\ndrops and reacquires the socket lock.  Its error path tries to decide\nwhether msg_tx names the local temporary message by comparing it with\nthe current value of psock-\u003ecork.\n\nThis comparison is unsafe when two threads send on the same socket:\n\n  Thread A                         Thread B\n  msg_tx \u003d psock-\u003ecork\n  sk_msg_alloc() fails\n  sk_stream_wait_memory()\n    releases the socket lock      acquires the socket lock\n                                  completes the cork\n                                  psock-\u003ecork \u003d NULL\n                                  frees the cork\n    reacquires the socket lock\n  msg_tx !\u003d psock-\u003ecork\n  sk_msg_free(msg_tx)\n\nThe stale cork is therefore mistaken for the local temporary message\nand freed again.  KASAN reported:\n\n  BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50\n  Read of size 4 at addr ffff88810c908800 by task poc/90\n  Call Trace:\n   sk_msg_free+0x49/0x50\n   tcp_bpf_sendmsg+0x14f5/0x1cc0\n   __sys_sendto+0x32c/0x3a0\n   __x64_sys_sendto+0xdb/0x1b0\n  Allocated by task 89:\n   __kasan_kmalloc+0x8f/0xa0\n   tcp_bpf_sendmsg+0x16b3/0x1cc0\n  Freed by task 91:\n   __kasan_slab_free+0x43/0x70\n   kfree+0x131/0x3c0\n   tcp_bpf_sendmsg+0xec3/0x1cc0\n\nmsg_tx can only name the stack-local tmp or the shared cork. Check for\ntmp directly so a changed psock-\u003ecork cannot turn a shared message into\nan apparent local one.\n\nBUG\u003db/545103427\nTEST\u003dpresubmit\nRELEASE_NOTE\u003dFixed CVE-2026-68284 in the Linux kernel.\n\ncos-patch: security-moderate\nFixes: 604326b41a6f (\"bpf, sockmap: convert to generic sk_msg interface\")\nChange-Id: Id2f769a019680d1a119ec2ba5414b2c0742c40d4\nSigned-off-by: Chengfeng Ye \u003cnicoyip.dev@gmail.com\u003e\nReviewed-by: Emil Tsalapatis \u003cemil@etsalapatis.com\u003e\nReviewed-by: Jakub Sitnicki \u003cjakub@cloudflare.com\u003e\nLink: https://lore.kernel.org/bpf/87fr18lmzo.fsf%40cloudflare.com/\nLink: https://lore.kernel.org/netdev/20260719161630.2901208-1-nicoyip.dev%40gmail.com/ [v1]\nLink: https://patch.msgid.link/20260724103856.3399001-1-nicoyip.dev@gmail.com\nSigned-off-by: Eduard Zingerman \u003ceddyz87@gmail.com\u003e\nSigned-off-by: Sasha Levin \u003csashal@kernel.org\u003e\nSigned-off-by: kevin liu \u003czhihuil@google.com\u003e\nReviewed-on: https://cos-review.googlesource.com/c/third_party/kernel/+/185049\nTested-by: Cusky Presubmit Bot \u003cpresubmit@cos-infra-prod.iam.gserviceaccount.com\u003e\nReviewed-by: Derek Taylor \u003cddtaylor@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "b9a58fde9c31b77f2b9cc29cdd304d9629dfa223",
      "old_mode": 33188,
      "old_path": "net/ipv4/tcp_bpf.c",
      "new_id": "132ffc13087f5a4fc47a2efafb9ddfb0a77be40b",
      "new_mode": 33188,
      "new_path": "net/ipv4/tcp_bpf.c"
    }
  ]
}
