{"id":"AZL-106734","summary":"CVE-2026-98374 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()\n\nWhen tcp_send_synack() replaces the cloned SYN skb at the head of the\nretransmit queue with a copy, it frees the original with\ntcp_rtx_queue_unlink_and_free() and only repairs tp-\u003ehighest_sack.\ntp-\u003eretransmit_skb_hint keeps pointing at the freed\nskbuff_fclone_cache object.\n\nThe dangling hint is read in tcp_verify_retransmit_hint() and used as\nthe root of the rbtree walk in tcp_xmit_retransmit_queue().  An\nunprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with\nan attacker-supplied ICMP fragmentation-needed message, after which a\nsimultaneous open frees the armed SYN skb:\n\n  BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)\n  Read of size 4 at addr ffff88800604d928 by task swapper/1/0\n  Call Trace:\n   tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316)\n   tcp_simple_retransmit (net/ipv4/tcp_input.c:3158)\n   tcp_v4_err (net/ipv4/tcp_ipv4.c:587)\n\nSync the hint to the copy.","modified":"2026-10-08T14:16:19.618646565Z","published":"2026-10-07T13:17:23Z","upstream":["CVE-2026-98374"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98374"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106734.json"}}],"schema_version":"1.9.0"}