-

CVE-2026-80845

xfrm: avoid lock inversion in nat keepalive work

In the Linux kernel, the following vulnerability has been resolved:

xfrm: avoid lock inversion in nat keepalive work

nat_keepalive_work() walks the state table while xfrm_state_walk()
holds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock,
which conflicts with the delete path taking the same locks in reverse
order via xfrm_state_delete() and __xfrm_state_delete(). This creates
an AB-BA deadlock that is reported by lockdep when a NAT keepalive
worker races with SA deletion.

Fix this by splitting the keepalive walk into two phases. First,
collect the candidate states while the walk holds xfrm_state_lock and
take a reference on each state. Then, after the walk completes, process
each collected state and acquire x->lock without nesting it under
xfrm_state_lock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae
Version < ea09210462316e5235a25eccb11ad0708d86615e
Status affected
Version f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae
Version < 5c86c895d1cac81a71ead3005084c6265cf6a7a5
Status affected
Version f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae
Version < 89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d
Status affected
Version f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae
Version < a9fa05b7a1246797748d15771052639e0d3cabf1
Status affected
Version f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae
Version < 763fe700b7c58ad64fe5202c5638848244dd4127
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ea09210462316e5235a25eccb11ad0708d86615e
https://git.kernel.org/stable/c/5c86c895d1cac81a71ead3005084c6265cf6a7a5
https://git.kernel.org/stable/c/89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d
https://git.kernel.org/stable/c/a9fa05b7a1246797748d15771052639e0d3cabf1
https://git.kernel.org/stable/c/763fe700b7c58ad64fe5202c5638848244dd4127