CVE-2026-68399 is a vulnerability in Linux Kernel
Published on August 10, 2026
bpf: Fix UAF in sock clone early bailouts
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix UAF in sock clone early bailouts
Similar to recent commit 9b51a6155d14 ("bpf,fork: wipe ->bpf_storage
before bailouts that access it"), sk_clone() performs an initial
shallow copy of the socket field ->sk_bpf_storage via sock_copy()
for the cloned socket newsk.
If sk_clone() bails out early (e.g. if sk_filter_charge() fails) prior
to calling bpf_sk_storage_clone(), newsk->sk_bpf_storage still points
to the parent socket's BPF local storage. When newsk is subsequently
freed via sk_free(), the deallocation path (__sk_destruct() ->
bpf_sk_storage_free()) destroys the parent socket's BPF local storage,
leading to a use-after-free (UAF) on the parent socket.
Fix this by resetting newsk->sk_bpf_storage to NULL immediately after
sock_copy() in sk_clone(), and remove the now redundant initialization
from bpf_sk_storage_clone().
Products Associated with CVE-2026-68399
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 6ac99e8f23d4b10258406ca0dd7bffca5f31da9d and below 14b49b5ab29979552c219a09e569b424fbbf4a6e is affected.
- Version 6ac99e8f23d4b10258406ca0dd7bffca5f31da9d and below 7cbd0c4cebe4c9f678d15e6b9ba975e1155a107f is affected.
- Version 5.2 is affected.
- Before 5.2 is unaffected.
- Version 7.1.6, <= 7.1.* is unaffected.
- Version 7.2-rc4, <= * is unaffected.