PT-2026-106559 · Linux · Linux
CVE-2026-98230
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
xfrm: use hlist del init rcu for state cache and state cache input
Commit 14acf9652e56 ("xfrm: defensively unhash xfrm state lists in
xfrm state delete") converted bydst/bysrc/byseq/byspi from
hlist del rcu() to hlist del init rcu() so that a second
xfrm state delete() on the same object becomes a no-op rather than a
write through LIST POISON pprev. It missed state cache and
state cache input, which kept hlist del rcu():
- hlist del rcu() leaves pprev = LIST POISON2 (non-NULL), so hlist unhashed() returns false.
- hlist del init rcu() leaves pprev = NULL, so hlist unhashed() returns true.
A second xfrm state delete() therefore enters hlist del() on the
already-deleted state cache/state cache input nodes and does
WRITE ONCE(*pprev, next) through LIST POISON2 — a write use-after-free
once the slab is reused. The corruption can in turn cause a subsequent
hlist for each entry rcu traversal to follow a dangling next pointer,
producing the read use-after-free reported in xfrm input state lookup().
Switch state cache and state cache input to hlist del init rcu() to
match the other four lists, closing the write use-after-free and, with
it, the read use-after-free it spawns.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux