HackerOne Disclosed Reports - 2026-04-30

0 Replies, 1 Views

Logo
High
resolved

Double fdrop on a socket through sys_netcontrol


Bug reported by SlidyBat was disclosed at May 1, 2026, 1:41 am   |   Double Free

The netcontrol syscall in the kernel had a vulnerability where the socket file descriptor was not properly validated when removing a socket from a netevent structure. This allowed an attacker to cause a double fdrop on a socket, potentially leading to a use-after-free condition.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)