-

CVE-2026-98231

xfrm: serialize state GC with device state flush

In the Linux kernel, the following vulnerability has been resolved:

xfrm: serialize state GC with device state flush

The deferred-device pass in xfrm_dev_state_flush() finds states under
xfrm_state_dev_gc_lock, but drops the lock before calling
xfrm_dev_state_free() because the driver callback may sleep.  The device
GC list does not hold an xfrm_state reference, so the state GC worker can
destroy the same state concurrently.

The race can proceed as follows:

  CPU 0                               CPU 1
  find x on the device GC list
  drop xfrm_state_dev_gc_lock
  read x->xso.dev
                                      xfrm_state_gc_destroy(x)
                                      xfrm_dev_state_free(x)
                                      xfrm_state_free(x)
  continue xfrm_dev_state_free(x)

Both paths can invoke the driver callback and drop the device reference.
CPU 0 can also access the xfrm_state after CPU 1 has freed it.

KASAN reported:

  BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0
  Read of size 8 at addr ffff88810bbaa960 by task poc/102

  Call Trace:
   xfrm_dev_state_free+0x24c/0x2a0
   xfrm_dev_state_flush+0x353/0x400
   xfrm_dev_event+0x26d/0x3a0
   notifier_call_chain+0xc0/0x280
   __dev_notify_flags+0x169/0x250
   netif_change_flags+0xe7/0x160
   dev_change_flags+0x96/0x220
   devinet_ioctl+0x7f4/0x1880

  Allocated by task 87:
   xfrm_state_alloc+0x1e/0x5c0
   xfrm_add_sa+0xe7f/0x5820
   xfrm_user_rcv_msg+0x4f3/0x940

  Freed by task 57:
   kmem_cache_free+0xcb/0x3d0
   xfrm_state_gc_task+0x4a8/0x650
   process_one_work+0x63a/0x1070

Serialize xfrm_state destruction against the deferred-device pass with a
mutex.  Keep xfrm_state_dev_gc_lock limited to list operations and retain
the existing callback and device-reference release ordering.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version d5f53edd43daf3e6e1633a49c561387f8f99e13f
Version < 937108dc0258d6ac69926b00bc53598c98986ee1
Status affected
Version 07b87f9eea0c30675084d50c82532d20168da009
Version < 39e41af3653ee45c985190dd97426f318918d201
Status affected
Version 07b87f9eea0c30675084d50c82532d20168da009
Version < 75fc4561772e2f9811abf39ed10443e6f4a4bc6c
Status affected
Version 07b87f9eea0c30675084d50c82532d20168da009
Version < 84e378395494963b1e581cf223a7cbeec8c0e2d6
Status affected
Version 07b87f9eea0c30675084d50c82532d20168da009
Version < 89fefad9f971bc637fb22373078144f2563c4be9
Status affected
Version 8ecee44464a4926c9bef989a1490b7394785f584
Status affected
Version 6.6.44
Version < 6.6.158
Status affected
Version 6.10.3
Version < 6.11
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.09
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/937108dc0258d6ac69926b00bc53598c98986ee1
https://git.kernel.org/stable/c/39e41af3653ee45c985190dd97426f318918d201
https://git.kernel.org/stable/c/75fc4561772e2f9811abf39ed10443e6f4a4bc6c
https://git.kernel.org/stable/c/84e378395494963b1e581cf223a7cbeec8c0e2d6
https://git.kernel.org/stable/c/89fefad9f971bc637fb22373078144f2563c4be9