7

CVE-2026-98230

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

In the Linux kernel, the following vulnerability has been resolved:

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete") converted bydst/bysrc/byseq/byspi from
hlist_del_rcu() to hlist_del_init_rcu() so that a second
__xfrm_state_delete() on the same object becomes a no-op rather than a
write through LIST_POISON pprev. It missed state_cache and
state_cache_input, which kept hlist_del_rcu():

- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so
  hlist_unhashed() returns false.
- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()
  returns true.

A second __xfrm_state_delete() therefore enters __hlist_del() on the
already-deleted state_cache/state_cache_input nodes and does
WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free
once the slab is reused. The corruption can in turn cause a subsequent
hlist_for_each_entry_rcu traversal to follow a dangling next pointer,
producing the read use-after-free reported in xfrm_input_state_lookup().

Switch state_cache and state_cache_input to hlist_del_init_rcu() to
match the other four lists, closing the write use-after-free and, with
it, the read use-after-free it spawns.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version aa48a18fdb0911572d133057cd579db704b87da4
Version < fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5
Status affected
Version 0045e3d80613cc7174dc15f189ee6fc4e73b9365
Version < 4748c27e2e6a1969e02f1df46e62f79d2799b80b
Status affected
Version 0045e3d80613cc7174dc15f189ee6fc4e73b9365
Version < 9b74a47a4cbd0d29faff4f3b199212c73e6b6220
Status affected
Version 0045e3d80613cc7174dc15f189ee6fc4e73b9365
Version < 2afb8dc1f4390f164db8352f8e685e126e9db566
Status affected
Version 5e4334dc39443645415450163ff5ff1ee7e79784
Status affected
Version 6.12.13
Version < 6.12.112
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.13
Status affected
Version 0
Version < 6.13
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.016
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5
https://git.kernel.org/stable/c/4748c27e2e6a1969e02f1df46e62f79d2799b80b
https://git.kernel.org/stable/c/9b74a47a4cbd0d29faff4f3b199212c73e6b6220
https://git.kernel.org/stable/c/2afb8dc1f4390f164db8352f8e685e126e9db566