PT-2026-106559 · Linux · Linux

CVE-2026-98230

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
xfrm: use hlist del init rcu for state cache and state cache input
Commit 14acf9652e56 ("xfrm: defensively unhash xfrm state lists in xfrm state delete") converted bydst/bysrc/byseq/byspi from hlist del rcu() to hlist del init rcu() so that a second xfrm state delete() on the same object becomes a no-op rather than a write through LIST POISON pprev. It missed state cache and state cache input, which kept hlist del rcu():
  • hlist del rcu() leaves pprev = LIST POISON2 (non-NULL), so hlist unhashed() returns false.
  • hlist del init rcu() leaves pprev = NULL, so hlist unhashed() returns true.
A second xfrm state delete() therefore enters hlist del() on the already-deleted state cache/state cache input nodes and does WRITE ONCE(*pprev, next) through LIST POISON2 — a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlist for each entry rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm input state lookup().
Switch state cache and state cache input to hlist del init rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98230

Produtos afetados

Linux