-

CVE-2026-64579

xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert

In the Linux kernel, the following vulnerability has been resolved:

xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert

xfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert
loop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or
fail. But its guard is inverted: it skips policies with prefixlen <
threshold and preallocates for the rest.

prefixlen < threshold is exactly when policy_hash_bysel() returns NULL and
the reinsert takes the allocating xfrm_policy_inexact_insert() path. So the
loop preallocates for the exact policies (which never allocate) and skips
the inexact ones, whose bin/node is then allocated GFP_ATOMIC during
reinsert. On failure the error path only WARN_ONCE()s and continues,
leaving a poisoned bydst node; the next rebuild's hlist_del_rcu()
dereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,
deterministic via failslab.

Invert the guard so preallocation covers exactly the reinserted policies;
the reinsert then allocates nothing and cannot fail.

Crash:
  Oops: general protection fault, probably for non-canonical address
  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI
  KASAN: maybe wild-memory-access in range [0xdead...]
  ...
  Workqueue: events xfrm_hash_rebuild
  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190
  RAX: dead000000000122   (LIST_POISON2 + offset)
  ...
  Call Trace:
   hlist_del_rcu (include/linux/rculist.h:599)
   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)
   process_one_work (kernel/workqueue.c:3322)
   worker_thread (kernel/workqueue.c:3486)
   kthread (kernel/kthread.c:436)
   ret_from_fork (arch/x86/kernel/process.c:158)
   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
   ...
  Kernel panic - not syncing: Fatal exception in interrupt
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < e48f4c3e3df35b34be719d72d737bbeaca77cf0c
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < 1cdeed9df1306f1a277e715600772640d63defa9
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < 43a4d510523779891cf8eca7ffb4a086b0b5d8bf
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < d9d9cc21cc90014724a14c447e3d587be9447107
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < 94c00391a5117530188334f740ce26d3f1256190
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < 7acc5ed2f33608a3d83b64f50a5766843b6e2485
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < 6aa3796d18a9fda953ad76a62b57bf6c145cb9ef
Status affected
Version 24969facd704a5f0dd8e08da86bf32a9ce972bee
Version < f38f8cce2f7e79775b3db7e8a5eacda04ac908e4
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.0
Status affected
Version 0
Version < 5.0
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107
https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190
https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485
https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef
https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4
https://git.kernel.org/stable/c/1cdeed9df1306f1a277e715600772640d63defa9
https://git.kernel.org/stable/c/43a4d510523779891cf8eca7ffb4a086b0b5d8bf
https://git.kernel.org/stable/c/e48f4c3e3df35b34be719d72d737bbeaca77cf0c