9.8

CVE-2026-68426

xfrm: fix stale skb->prev after async crypto steals a GSO segment

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix stale skb->prev after async crypto steals a GSO segment

skb_gso_segment() leaves the segment list head with ->prev pointing at
the last segment, an invariant validate_xmit_skb_list() relies on when
it sets its tail pointer (tail = skb->prev).

When validate_xmit_xfrm() walks a GSO list and some segments are stolen
by async crypto (->xmit() returns -EINPROGRESS), those segments are
unlinked from the list but the head ->prev is never updated.  If the
last segment is the one stolen, the returned head still has ->prev
pointing at it, even though it is now owned by the crypto engine and may
be freed.  validate_xmit_skb_list() later does tail->next = skb, writing
through that stale pointer -- a use-after-free.

Repoint skb->prev at the last retained segment before returning.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f53c723902d1ac5f0b0a11d7c9dcbff748dde74e
Version < 33e1b0d25ca0d2818c635ff80e6aa0d295e08a98
Status affected
Version f53c723902d1ac5f0b0a11d7c9dcbff748dde74e
Version < bbca7cc3b2b4b10afbfee99b81d9ee78f5423046
Status affected
Version f53c723902d1ac5f0b0a11d7c9dcbff748dde74e
Version < 3f4c3919baf0944ad96580467c302bc6c7758b00
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.16
Status affected
Version 0
Version < 4.16
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.297
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/33e1b0d25ca0d2818c635ff80e6aa0d295e08a98
https://git.kernel.org/stable/c/bbca7cc3b2b4b10afbfee99b81d9ee78f5423046
https://git.kernel.org/stable/c/3f4c3919baf0944ad96580467c302bc6c7758b00