« Volver al listado

CVE-2026-80845

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfrm: avoid lock inversion in nat keepalive work

nat_keepalive_work() walks the state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock, which conflicts with the delete path taking the same locks in reverse order via xfrm_state_delete() and __xfrm_state_delete(). This creates an AB-BA deadlock that is reported by lockdep when a NAT keepalive worker races with SA deletion.

Fix this by splitting the keepalive walk into two phases. First, collect the candidate states while the walk holds xfrm_state_lock and take a reference on each state. Then, after the walk completes, process each collected state and acquire x->lock without nesting it under xfrm_state_lock.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80845",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
              "lessThan": "ea09210462316e5235a25eccb11ad0708d86615e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
              "lessThan": "5c86c895d1cac81a71ead3005084c6265cf6a7a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
              "lessThan": "89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
              "lessThan": "a9fa05b7a1246797748d15771052639e0d3cabf1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae",
              "lessThan": "763fe700b7c58ad64fe5202c5638848244dd4127",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_nat_keepalive.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_nat_keepalive.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:13.173",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5c86c895d1cac81a71ead3005084c6265cf6a7a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/763fe700b7c58ad64fe5202c5638848244dd4127",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a9fa05b7a1246797748d15771052639e0d3cabf1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea09210462316e5235a25eccb11ad0708d86615e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: avoid lock inversion in nat keepalive work\n\nnat_keepalive_work() walks the state table while xfrm_state_walk()\nholds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock,\nwhich conflicts with the delete path taking the same locks in reverse\norder via xfrm_state_delete() and __xfrm_state_delete(). This creates\nan AB-BA deadlock that is reported by lockdep when a NAT keepalive\nworker races with SA deletion.\n\nFix this by splitting the keepalive walk into two phases. First,\ncollect the candidate states while the walk holds xfrm_state_lock and\ntake a reference on each state. Then, after the walk completes, process\neach collected state and acquire x->lock without nesting it under\nxfrm_state_lock."
    }
  ],
  "lastModified": "2026-09-04T16:18:13.173",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}