7.8

CVE-2026-98241

ipv6: xfrm: use full sockets in local error paths

In the Linux kernel, the following vulnerability has been resolved:

ipv6: xfrm: use full sockets in local error paths

xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it
always pointed at a full IPv6 socket.

That is not guaranteed. TCP SYN-ACK skbs can be owned by a
TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the
full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower
MTU, the local PMTU/error handling path can reach these callbacks with that
mini-socket still attached to the skb.

The callbacks then miscast the request socket as a full inet/IPv6 socket and
can read beyond the request_sock allocation when they access inet_sock or
ipv6_pinfo state.

Resolve the owner with skb_to_full_sk() in both callbacks and bail out when
no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error
logic, which already reasons about full sockets with skb_to_full_sk().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < b1a88633c36d2cbc3831382f3846754d344276fd
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < 904a0e827d0d7189271a3a2eb648293809f25efc
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < 675919e08ce266b8cac11fd9af29170e762a480f
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < 60459c670329d586a58db5d8f811fa5accfe4862
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < ca3d68c3213475b53db6647e159dc73bd1af5ab1
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < 4c030a0400ebfd2318361c923a88103b2c67c49f
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8
Status affected
Version dd767856a36e00b631d65ebc4bb81b19915532d6
Version < 6973a21ee73c5567f883813c8ef414774b45892f
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.2
Status affected
Version 0
Version < 3.2
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.028
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd
https://git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc
https://git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f
https://git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862
https://git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1
https://git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f
https://git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8
https://git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f