PT-2026-106699 · Linux · Linux
CVE-2026-98370
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrm state netlink() builds the ALLOCSPI response with
dump one state(), which already calls alloc compat() with the response
skb and header.
xfrm alloc userspi() then calls alloc compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm userspi info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag list.
A multicast clone of the request shares skb shared info and can observe
that child. xfrm user rcv msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump one state(), and no child is attached to the
inbound request.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux