-

CVE-2026-98370

xfrm: fix compat ALLOCSPI request use-after-free

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix compat ALLOCSPI request use-after-free

xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.

xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.

A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.

Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < 17893987e52918c23945c42e47e894a936305a25
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < bb63ab52a18273ec68340ac49aebbaa7b514ccd5
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < 248433942155b42a0ef04a5806c8aca024ea7c33
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < e70f639aee2ff0def155c256cace9e0f81d998e2
Status affected
Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version < d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4
https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25
https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810
https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718
https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5
https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33
https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2
https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320