7.8

CVE-2026-98369

xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()

In the Linux kernel, the following vulnerability has been resolved:

xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()

syzbot reported a suspicious RCU usage warning in ip6_pkt_drop():

  WARNING: suspicious RCU usage in ip6_pkt_drop
  include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!

  Call Trace:
   __in6_dev_get_safely include/net/addrconf.h:389 [inline]
   ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620
   ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651
   xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806
   process_one_work kernel/workqueue.c:3322 [inline]
   process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405
   worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486

When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through
workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue,
the reinjection loop ceased running in softirq context. Workqueue workers
run in process context where local_bh_disable() does not enter an RCU
read-side critical section under CONFIG_PREEMPT_RCU.

Because finish callbacks (such as ip6_rcv_finish) expect to run under an
RCU read lock (performing route lookups, l3mdev lookups, and accessing
RCU-protected data structures), invoking them in workqueue context without
rcu_read_lock() triggers RCU lockdep warnings.

Furthermore, packets queued to the workqueue via xfrm_trans_queue_net()
may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).
Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev
with blackhole_netdev, so dst entries do not keep skb->dev alive while
queued in the workqueue.

Fix these issues by:
1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the
   caller's RCU section to ensure dst is reference-counted before queuing.
2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue
   deferral so skb->dev remains valid during finish() callback processing.
3. Acquiring rcu_read_lock() around the finish callback invocation loop in
   xfrm_trans_reinject().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7d98b26684cb2390729525b341ea099f0badbe18
Version < 41e47f1664be86c91326f0afe0504a1162d00907
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < 6601d91a85761f33351c71e04ec0bbd294ca07ce
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < 0cda8273265d30cac6423834fd7d4acb75f04fdb
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < 68a317b4aec8ca1868a39d69e40f9e29baa4f40a
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < 6eb3b071be8e260543c604550c54dac66e6b174b
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < 664fc0941df7c1918b2cd4de6ee00469ba77d8e4
Status affected
Version 4f4920669d21e1060b7243e5118dc3b71ced1276
Version < d2f5082f9e84653fa1a9e8aebaaff23e688f5e19
Status affected
Version f520075da484306bbb8425afd2c42404ba74816f
Status affected
Version 130d9e5017ade1b81d16783563edb38c12a2eab7
Status affected
Version 5.15.75
Version < 5.15.222
Status affected
Version 5.19.17
Version < 5.20
Status affected
Version 6.0.3
Version < 6.1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.1
Status affected
Version 0
Version < 6.1
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.033
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/41e47f1664be86c91326f0afe0504a1162d00907
https://git.kernel.org/stable/c/6601d91a85761f33351c71e04ec0bbd294ca07ce
https://git.kernel.org/stable/c/0cda8273265d30cac6423834fd7d4acb75f04fdb
https://git.kernel.org/stable/c/68a317b4aec8ca1868a39d69e40f9e29baa4f40a
https://git.kernel.org/stable/c/6eb3b071be8e260543c604550c54dac66e6b174b
https://git.kernel.org/stable/c/664fc0941df7c1918b2cd4de6ee00469ba77d8e4
https://git.kernel.org/stable/c/d2f5082f9e84653fa1a9e8aebaaff23e688f5e19