PT-2026-106699 · Linux · Linux

CVE-2026-98370

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrm state netlink() builds the ALLOCSPI response with dump one state(), which already calls alloc compat() with the response skb and header.
xfrm alloc userspi() then calls alloc compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm userspi info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag list.
A multicast clone of the request shares skb shared info and can observe that child. xfrm user rcv msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat translation from dump one state(), and no child is attached to the inbound request.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98370

Affected Products

Linux