Description
In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict check when using hash2 When binding a udp_sock to a local address and port, UDP uses two hashes (udptable->hash and udptable->hash2) for collision detection. The current code switches to -hash2- when hslot->count > 10. -hash2- is keyed by local address and local port. -hash- is keyed by local port only. The issue can be shown in the following bind sequence (pseudo code): bind(fd1, -[fd00::1]:8888-) bind(fd2, -[fd00::2]:8888-) bind(fd3, -[fd00::3]:8888-) bind(fd4, -[fd00::4]:8888-) bind(fd5, -[fd00::5]:8888-) bind(fd6, -[fd00::6]:8888-) bind(fd7, -[fd00::7]:8888-) bind(fd8, -[fd00::8]:8888-) bind(fd9, -[fd00::9]:8888-) bind(fd10, -[fd00::10]:8888-) /* Correctly return -EADDRINUSE because -hash- is used * instead of -hash2-. udp_lib_lport_inuse() detects the * conflict. */ bind(fail_fd, -[::]:8888-) /* After one more socket is bound to -[fd00::11]:8888-, * hslot->count exceeds 10 and -hash...
- Published
- 2026-04-22 14:16:48
- Affected versions
- unknown
- Type
- Core software
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Operating systems
- Linux