« Volver al listado

CVE-2026-98230

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second __xfrm_state_delete() on the same object becomes a no-op rather than a write through LIST_POISON pprev. It missed state_cache and state_cache_input, which kept hlist_del_rcu():

A second __xfrm_state_delete() therefore enters __hlist_del() on the already-deleted state_cache/state_cache_input nodes and does WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free once the slab is reused.

Leer descripción completaMostrar menos

The corruption can in turn cause a subsequent hlist_for_each_entry_rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm_input_state_lookup().

Switch state_cache and state_cache_input to hlist_del_init_rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.

Detalles técnicos trazas, registros y código del informe original
- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so
  hlist_unhashed() returns false.
- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()
  returns true.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98230",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "aa48a18fdb0911572d133057cd579db704b87da4",
              "lessThan": "fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0045e3d80613cc7174dc15f189ee6fc4e73b9365",
              "lessThan": "4748c27e2e6a1969e02f1df46e62f79d2799b80b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0045e3d80613cc7174dc15f189ee6fc4e73b9365",
              "lessThan": "9b74a47a4cbd0d29faff4f3b199212c73e6b6220",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0045e3d80613cc7174dc15f189ee6fc4e73b9365",
              "lessThan": "2afb8dc1f4390f164db8352f8e685e126e9db566",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5e4334dc39443645415450163ff5ff1ee7e79784",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.13",
              "lessThan": "6.12.112",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_state.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_state.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:10.397",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2afb8dc1f4390f164db8352f8e685e126e9db566",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4748c27e2e6a1969e02f1df46e62f79d2799b80b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b74a47a4cbd0d29faff4f3b199212c73e6b6220",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: use hlist_del_init_rcu for state_cache and state_cache_input\n\nCommit 14acf9652e56 (\"xfrm: defensively unhash xfrm_state lists in\n__xfrm_state_delete\") converted bydst/bysrc/byseq/byspi from\nhlist_del_rcu() to hlist_del_init_rcu() so that a second\n__xfrm_state_delete() on the same object becomes a no-op rather than a\nwrite through LIST_POISON pprev. It missed state_cache and\nstate_cache_input, which kept hlist_del_rcu():\n\n- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so\n  hlist_unhashed() returns false.\n- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()\n  returns true.\n\nA second __xfrm_state_delete() therefore enters __hlist_del() on the\nalready-deleted state_cache/state_cache_input nodes and does\nWRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free\nonce the slab is reused. The corruption can in turn cause a subsequent\nhlist_for_each_entry_rcu traversal to follow a dangling next pointer,\nproducing the read use-after-free reported in xfrm_input_state_lookup().\n\nSwitch state_cache and state_cache_input to hlist_del_init_rcu() to\nmatch the other four lists, closing the write use-after-free and, with\nit, the read use-after-free it spawns."
    }
  ],
  "lastModified": "2026-10-06T09:18:10.397",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}