udp: Unhash auto-bound connected sk from 4-tuple hash table when disconnected.
Published Mar 25, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.12%
Description
Let's say we bind() an UDP socket to the wildcard address with a non-zero port, connect() it to an address, and disconnect it from the address.
bind() sets SOCK_BINDPORT_LOCK on sk->sk_userlocks (but not SOCK_BINDADDR_LOCK), and connect() calls udp_lib_hash4() to put the socket into the 4-tuple hash table.
Then, __udp_disconnect() calls sk->sk_prot->rehash(sk).
It computes a new hash based on the wildcard address and moves the socket to a new slot in the 4-tuple hash table, leaving a garbage in the chain that no packet hits.
Let's remove such a socket from 4-tuple hash table when disconnected.
Note that udp_sk(sk)->udp_portaddr_hash needs to be udpated after udp_hash4_dec(hslot2) in udp_unhash4().
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.13StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.13
- Version 6.18.17StatusunaffectedConstraints<=6.18.*
- Version 6.19.7StatusunaffectedConstraints<=6.19.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.13.1 · < 6.18.17
- ≥ 6.19 · < 6.19.7
- 6.13
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects UDP socket handling when applications repeatedly connect and disconnect sockets bound to wildcard addresses. The stale hash entries accumulate in the 4-tuple hash table, causing lookup inefficiency and potential hash chain degradation. The impact is gradual performance degradation rather than an immediate system crash.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.12% (0.00121) | 1.67th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.12% (0.00121) | 2.21th | v5 (v2026.06.15) |
| Mar 25, 2026 | 0.02% (0.00017) | 3.93th | v4 (v2025.03.14) |
References (8)
- https://access.redhat.com/security/cve/CVE-2026-23331 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2451190 Issue Tracking
- https://git.kernel.org/stable/c/3b8f104880c104151f8c30f2f89df81fb59a286c Patch
- https://git.kernel.org/stable/c/6996a2d2d0a64808c19c98002aeb5d9d1b2df6a4 Patch
- https://git.kernel.org/stable/c/b955350778b8715e1b7885179979b3a68221c0fb Patch
- https://lore.kernel.org/linux-cve-announce/2026032532-CVE-2026-23331-735b@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-23331
- https://www.cve.org/CVERecord?id=CVE-2026-23331
Change history (0)
No recorded changes yet.