-
CVE-2026-98370
- EPSS 0.17%
- Veröffentlicht 06.10.2026 08:46:54
- Zuletzt bearbeitet 06.10.2026 09:18:31
- Erkennungen
xfrm: fix compat ALLOCSPI request use-after-free
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
494f2bee9d8d0ebcfa249ac41bed7fed26d119b4
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
17893987e52918c23945c42e47e894a936305a25
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
bb63ab52a18273ec68340ac49aebbaa7b514ccd5
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
248433942155b42a0ef04a5806c8aca024ea7c33
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
e70f639aee2ff0def155c256cace9e0f81d998e2
Status
affected
Version
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Version <
d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.10
Status
affected
Version
0
Version <
5.10
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.54
Status
unaffected
Version <=
7.2.*
Version
7.2.8
Status
unaffected
Version <=
*
Version
7.3-rc4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.059 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4
https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25
https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810
https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718
https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5
https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33
https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2
https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320