CVE-2026-42945

Published May 13, 2026

Last updated 3 days ago

CVSS critical 9.2
NGINX
Openresty
Ubuntu
ICS
Port (443)
HTTP
NGINX Plus
NGINX Open Source

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-42945 is a heap buffer overflow vulnerability found in the `ngx_http_rewrite_module` of NGINX Plus and NGINX Open Source. This flaw occurs when a `rewrite` directive is immediately followed by another `rewrite`, `if`, or `set` directive, and an unnamed Perl-Compatible Regular Expression (PCRE) capture (such as `$1` or `$2`) is used within a replacement string that contains a question mark (`?`). An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests. This can lead to a heap buffer overflow in the NGINX worker process, causing it to restart. Additionally, on systems where Address Space Layout Randomization (ASLR) is disabled, this vulnerability could potentially allow for code execution.

Description
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source
f5sirt@f5.com
NVD status
Modified
Products
dos, nginx_gateway_fabric, nginx_ingress_controller, nginx_instance_manager, nginx_open_source, nginx_plus, waf

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

f5sirt@f5.com
CWE-122
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-131

Social media

Hype score
Not currently trending
  1. I just completed CVE-2026-42945: Nginx Rift room on TryHackMe! Exploit NGINX Rift, an unauthenticated heap overflow RCE in NGINX's rewrite module since 2008. https://t.co/pry7VUPtw9 #tryhackme via @tryhackme

    @BLukonsolo

    15 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-42945 (NGINX Rift): critical heap overflow in the nginx rewrite module, exploited in the wild. Get the Nuclei detection template and scan with Sn1per. https://t.co/qvTqdBqpsc #CVE-2026-42533 #bugbounty #netsec #infosec #offsec #redteam #EASM #infosecurity

    @xer0dayz

    4 Aug 2026

    383 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Here's the AILA write-up for CVE-2026-42533 - TwinWalk with PoC It started with a single prompt for CVE-2026-42945 and it spawned 378 sub investigations. 127M input tokens / 21M output tokens are burned and it costed me nothing. (free tier models)

    @echel0n_1881

    18 Jul 2026

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. NGINX Rift (CVE-2026-42945): cuando una vulnerabilidad en el proxy se convierte en un problema de plataforma | Juan Almodóvar | Lee esta publicación y más en la web de Araintel https://t.co/4yg0eUXzkC

    @araintelhacking

    14 Jun 2026

    42 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-42945: nginx has a critical vuln (CVE-2026-42945). Patched packages are live for AlmaLinux 8, 9, 10 & Kitten 10. Two commands and a restart and you're done. Don't sleep on this one!

    @lyrie_ai

    9 Jun 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 NGINX sürümleriniz güncel değilse güncelleyin; Rift (CVE-2026-42945) güvenlik açığı 1.30.0 ve öncesini etkiliyor. PoolSlip (CVE-2026-9256) güvenlik açığı 1.31.0 ve öncesini etkiliyor. Patchlenmiş sürümler: Nginx Open Source için 1.30.2 (stable) ya da

    @ridvanyagli

    8 Jun 2026

    206 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Top 5 Trending CVEs: 1 - CVE-2026-9366 2 - CVE-2026-42945 3 - CVE-2026-46640 4 - CVE-2026-49261 5 - CVE-2020-0022 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    8 Jun 2026

    115 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ⚠️ ثغرة حرجة في NGINX تحت استغلال فعلي بعد نشر PoC، رصدت VulnCheck محاولات خلال 3 أيام من الإفصاح المعرّف : CVE-2026-42945 المنتج : NGINX (F5) الحل : Apply F5 security advisory patches #CVE #NGINX

    @KasperskyDev

    7 Jun 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. 05:06 UTC: CVE-2026-42945 disclosed. ⚠️CVE-2026-42945: RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngxhttprewritem

    @lyrie_ai

    7 Jun 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. 02:35 UTC: CVE-2026-42945 disclosed. 🚨Alert🚨 CVE-2026-42945: A Critical Heap Buffer Overflow in NGINX. 🧐Credit by depthfirst: 📊 86 0day Intel: 🚨Alert🚨 CVE-2026-42945: A Critical Heap Buffer Overflow in NGINX.

    @lyrie_ai

    7 Jun 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. CVE-2026-42945. Source: X search for CVE-2026 critical Posted: 2026-05-19T20:34:16.000Z Likes: 24

    @lyrie_ai

    7 Jun 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 安全圈最近投喂的PoC仓库一堆跑不动的,但这个poc-lab有点意思。每个CVE目录配好了exploit脚本和复现指南,从Linux内核到Chrome、Redis、Notepad++,覆盖的都是今年高严重性漏洞。最近更新的CVE-2026-48778 Notepad++ RCE和CVE-20

    @vintcessun

    1 Jun 2026

    37 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  13. CVE-2026-42945 - NGINX vulnerability https://t.co/tT8DtrcDYC https://t.co/WwRxZKYfXU

    @SirajD_Official

    31 May 2026

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-42945 - NGINX vulnerability https://t.co/LSrXs9SU2Q https://t.co/x0OUZWI8Tb

    @CloudVirtues

    31 May 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-42945 - NGINX vulnerability https://t.co/XtiasWkTSq https://t.co/ZEA394flyz

    @Guru0791

    30 May 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2026-42945 - NGINX vulnerability https://t.co/FeWBuYnSeE https://t.co/m58UYqC9rK

    @scandaletti

    29 May 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. ⚠️ ثغرة حرجة في خادم ويب واسع الانتشار تتيح تنفيذ كود عن بُعد دون مصادقة، باستغلال نشط مرصود. المعرّف : CVE-2026-42945 الخطورة : 9.2 (CVSSv4) - Critical المتأثر : NGINX OSS ≤ 1.

    @KasperskyDev

    29 May 2026

    292 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. NGINX 1.31.0 のゼロデイ脆弱性 nginx-poolslip (CVE-N/A) を検出:ASLR バイパスによる RCE の可能性 https://t.co/cD85vEmFd3 この問題の原因は、 NGINX の内部にあるメモリプール管理メカニズムの不具合にあります。先日に修正

    @iototsecnews

    28 May 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. The NGINX Poolslip saga is a masterclass in why single patches fail. They fixed the buffer overflow in Rift (CVE-2026-42945) but left the underlying memory pool attack surface wide open. Now the same module has a second critical CVE. Patch the root cause, not just the symptom.

    @da7rkx0

    27 May 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 BREAKING: 1/3 of the internet is under active attack. Two critical zero-days (CVE-2026-42945 & CVE-2026-9256) just hit NGINX. The craziest part? The first bug hid in the codebase for 18 YEARS before an AI audit found it. Here is why this is a nightmare 🧵👇 https:/

    @da7rkx0

    27 May 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. #NGINX CVE-2026-42945 #Exploited in the Wild, Causing #WorkerCrashes and Possible #RCE https://t.co/IPQBkmqrIB

    @miguelcarvajalm

    25 May 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. NGINX の深刻な RCE 脆弱性 CVE-2026-42945:公開直後から実環境での悪用を確認 https://t.co/RCLSofJSxR 今回の NGINX の脆弱性 CVE-2026-42945 は、ヒープバッファ・オーバーフローというプログラムの不具合が原因となってい

    @iototsecnews

    25 May 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Recent exploits: Critical NGINX vulnerability (CVE-2026-42945) active. Also, TLS backends allowing rogue CA cert loading (CVE-2026-8723) & Google API keys lingering post-deletion threaten data integrity in transit. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    24 May 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CRITICAL NGINX FLAW! An 18-year-old bug 'NGINX Rift' (CVE-2026-42945) is actively exploited for DoS & RCE. Affects millions of web servers. Patch immediately! #NGINX #CVE #Infosec #PatchNow 🌐 cyber[.]netsecops[.]io https://t.co/YLqgqNVbyF

    @NetSecIO

    24 May 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. #躺着打工 CVE-2026-42945 毁了我的周末。

    @ieasterfan

    24 May 2026

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. NEW THREAT INTEL: CVE-2026-9256 Nginx-poolslip - Pre-auth heap overflow, bypasses CVE-2026-42945 patch. 9 detections, 15 IOCs. https://t.co/HThqQ69S36 #ThreatIntel #NGINX https://t.co/y7pFDfXADo

    @threadlinqs

    23 May 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Top 5 Trending CVEs: 1 - CVE-2026-42945 2 - CVE-2026-46333 3 - CVE-2026-9082 4 - CVE-2026-31431 5 - CVE-2025-34291 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 May 2026

    267 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. ⚠️CVE-2026-42945: RCE Proof of concept for CVE-2026-42945, a critical heap buffer overflow in NGINX's ngx_http_rewrite_module introduced in 2008 GitHub: https://t.co/4hnYDzPM0b https://t.co/wtz8Kt74G5

    @Anastasis_King

    22 May 2026

    2427 Impressions

    10 Retweets

    42 Likes

    18 Bookmarks

    0 Replies

    0 Quotes

  29. Top 5 Trending CVEs: 1 - CVE-2026-42945 2 - CVE-2026-46333 3 - CVE-2026-0265 4 - CVE-2020-2033 5 - CVE-2026-33278 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    21 May 2026

    145 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 1/ lagi iseng googling nginx, eh malah nemuin berita ada 2 CVE critical baru 😅 CVE-2026-42945 (NGINX Rift) & CVE-2026-8711 keduanya CVSS 9.2 — alias critical langsung cek server production 🧵

    @r00teen

    21 May 2026

    57 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  31. NGINX の深刻な脆弱性 CVE-2026-42945 が FIX:RCE と PoC の登場 https://t.co/qXmiTPEh6J 今回の脆弱性 CVE-2026-42945 は、NGINX の内部で行われる 2段階の処理プロセスにおける “状態の不整合” が原因で発生しています。第 1段

    @iototsecnews

    21 May 2026

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. NGINX njs の CVE-2026-8711(CVSS 9.2)を解説 同日公開の NGINX Rift(CVE-2026-42945)と比較すると影響範囲の違いが重要です。 ・影響は 3 条件が AND で揃った場合のみ ・修正版: njs 0.9.9 以降へ更新 ・NGINX Rift(PoC 公開・

    @MyTechBlogJP

    20 May 2026

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. مجدد برای نسخه های اخر nginx 1.31.0 آسیب پذیری منتشر شده. CVE بحرانی RCE. 😑 لعنت به باعث و بانی قطع اینترنت با این همه آسیب پذیری غیر قابل اپدیت. CVE-2026-42945

    @Agent15A

    20 May 2026

    153 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CVE-2026-42945 "NGINX Rift" ثغرة heap buffer overflow في ngx_http_rewrite_module موجودة منذ 2008 وتصيب كل إصدارات NGINX حتى 1.30.0. مهاجم غير مصادق يمكنه RCE عبر طلب HTTP واحد. CVSS 9.2 Critical. اكتشفها نظام

    @KasperskyDev

    20 May 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. CVE-2026-42945: ‼️🚨 MAJOR IMPACT: The 18-year-old NGINX critical RCE vulnerability "NGINX Rift" (CVE-2026-42945) now WORKS with ASLR turned ON. PoC code with the ASLR bypass has just been published on GitHub.

    @lyrie_ai

    20 May 2026

    107 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  36. NGINXの脆弱性:18年前から存在する重大な欠陥CVE-2026-42945が悪用され、サーバーがクラッシュする事態が発生 NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers #DailyCyberSecurity (May 19) https://t.co/

    @foxbook

    20 May 2026

    253 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  37. CVE-2026-42945: CVE-2026-42945 ⚠️ NGINX – Heap Overflow / Possible RCE Actively Exploited in the Wild (CVSS 9.2) A heap-based buffer overflow in ngxhttprewritemodule affects NGINX Open Source and NGINX Plus ≤1.30.0. Crafted HTTP requests can trigger worker crashes and…

    @lyrie_ai

    20 May 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  38. CVE-2026-42945: Critical 18-year-old "NGINX Rift" flaw CVE-2026-42945 is under active exploitation. Learn how to patch your proxies and block the unauthenticated heap overflow #NGINXRift #CVE202642945 #Infosec2026 #WebSecurity #SysAdmin #DevSecOps #AppSec #BufferOverflow…

    @lyrie_ai

    20 May 2026

    158 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  39. CVE-2026-42945. Source: X search for RCE 2026 exploit Posted: 2026-05-18T10:18:43.000Z Likes: 296

    @lyrie_ai

    20 May 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  40. CVE-2026-42945. 0day Intel: Experts warn of active exploitation of critical NGINX flaw CVE-2026-42945 https:

    @lyrie_ai

    19 May 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  41. nginx CVE-2026-42945 no. you _do not have to_ upgrade. only if you use rewrite+set directives and/or run shared hosting. another cve being used by infosec to satisfy their adhd. https://t.co/80I6nGUwuc

    @bubble_email

    19 May 2026

    27 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  42. Top 5 Trending CVEs: 1 - CVE-2026-2276 2 - CVE-2026-42945 3 - CVE-2026-20182 4 - CVE-2026-40369 5 - CVE-2026-29205 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    19 May 2026

    140 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 📌 استغلال ثغرة NGINX CVE-2026-42945 في البرية، مما يؤدي إلى تعطل العاملين واحتمالية تنفيذ الأوامر عن بعد 🛡️ الفئة: ثغرة 📝 الملخص: تم استغلال ثغرة أمان حديثة في

    @GMashari

    19 May 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers https://t.co/c8OBGs9dcT The post NGINX Rift: Critical 18-Year-Old Flaw CVE-2026-42945 Actively Exploited to Crash Servers appeared first on Daily CyberSecurity. Related posts: 30-Year-Ol

    @f1tym1

    19 May 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨 Critical NGINX flaw is now being actively exploited — attackers are weaponizing CVE-2026-42945 just days after disclosure, putting millions of exposed servers at immediate risk 👇 #aiz_cyber #CVE #ThreatIntel https://t.co/wJcfDOzqaK

    @Aiz_Cyber

    19 May 2026

    66 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 【NGINX CVE-2026-42945、公開直後に悪用観測】 NGINXのngx_http_rewrite_moduleに関するCVE-2026-42945が、攻撃者に悪用されていると報じられています。特定のrewrite設定条件下でヒープバッファオーバーフローが発生し、ワ

    @01ra66it

    19 May 2026

    193 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) https://t.co/yxCIMMPPBm

    @ninp0

    19 May 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Linode: Critical NGINX heap overflow CVE-2026-42945 — patch now If you run NGINX on Linode instances or in images you deploy on Linode, CVE-2026-42945 is a critical heap buffer overflow that places unpatched deployments at elevated risk —… Read more → https://t.co/CrNQa

    @changewatchdev

    18 May 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Legacy exposure keeps paying off for attackers. CVE-2026-42945 makes NGINX rewrite chains a live patch pr… CVE-2026-42945 is now being exploited against NGINX. Patch exposed rewrite-based deployment… 🔗 Read → https://t.co/kMqpwbgPjZ

    @fynn_JourX

    18 May 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨 NGINX Rift (CVE-2026-42945) Kritik Açığı Aktif Olarak İstismar Ediliyor 📅 18 Mayıs 2026 · 16:29 (TR) Siber saldırganlar, geçtiğimiz hafta ortaya çıkan ve NGINX Rift olarak adlandırılan kritik bir güvenlik açığını (CVE-2026-42945) aktif olarak sömür

    @TheNetworkGhost

    18 May 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

  1. In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves sock->sk pointing at the freed object: if (tipc_sk_insert(tsk)) { sk_free(sk); pr_warn("Socket create failed; port number exhausted\n"); return -EINVAL; } This is harmless for plain socket(): the syscall layer clears sock->ops before releasing, so tipc_release() is never called. It is not harmless on the accept() path. tipc_accept() creates the pre-allocated child socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then fput()s the new file, so __sock_release() -> tipc_release() runs lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the sk_lock spinlock. tipc_release() already guards this exact "failed accept() releases a pre-allocated child" case with "if (sk == NULL) return 0;", but the guard is bypassed because tipc_sk_create() left sock->sk non-NULL (dangling) rather than NULL. Clear sock->sk on the failed-insert path so the existing tipc_release() NULL check fires and the use-after-free is avoided. The tipc_sk_insert() failure is reached when the per-netns socket rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M elements) -- i.e. once a netns holds ~2M TIPC sockets every insert returns -E2BIG. BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839) Write of size 8 at addr ffff8880047cdc38 by task init/1 lock_sock_nested (net/core/sock.c:3839) tipc_release (net/tipc/socket.c:638) __sock_release (net/socket.c:710) sock_close (net/socket.c:1501) __fput (fs/file_table.c:512) Allocated by task 1: sk_alloc (net/core/sock.c:2308) tipc_sk_create (net/tipc/socket.c:487) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034) Freed by task 1: __sk_destruct (net/core/sock.c:2391) tipc_sk_create (net/tipc/socket.c:504) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034)CVE-2026-68117

References

Sources include official advisories and independent security research.