PT-2026-106699 · Linux · Linux
CVE-2026-98370
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrm state netlink() builds the ALLOCSPI response with
dump one state(), which already calls alloc compat() with the response
skb and header.
xfrm alloc userspi() then calls alloc compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm userspi info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag list.
A multicast clone of the request shares skb shared info and can observe
that child. xfrm user rcv msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump one state(), and no child is attached to the
inbound request.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux