Back

MEDIUM

udp: Unhash auto-bound connected sk from 4-tuple hash table when disconnected.

Published Mar 25, 2026

Description

Let's say we bind() an UDP socket to the wildcard address with a non-zero port, connect() it to an address, and disconnect it from the address.

bind() sets SOCK_BINDPORT_LOCK on sk->sk_userlocks (but not SOCK_BINDADDR_LOCK), and connect() calls udp_lib_hash4() to put the socket into the 4-tuple hash table.

Then, __udp_disconnect() calls sk->sk_prot->rehash(sk).

It computes a new hash based on the wildcard address and moves the socket to a new slot in the 4-tuple hash table, leaving a garbage in the chain that no packet hits.

Let's remove such a socket from 4-tuple hash table when disconnected.

Note that udp_sk(sk)->udp_portaddr_hash needs to be udpated after udp_hash4_dec(hslot2) in udp_unhash4().

Affected products

Remediation

Red Hat statement

This flaw affects UDP socket handling when applications repeatedly connect and disconnect sockets bound to wildcard addresses. The stale hash entries accumulate in the 4-tuple hash table, causing lookup inefficiency and potential hash chain degradation. The impact is gradual performance degradation rather than an immediate system crash.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Mar 25, 2026
Updated May 11, 2026
Reserved Jan 13, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 25, 2026