« Volver al listado

CVE-2026-98231

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfrm: serialize state GC with device state flush

The deferred-device pass in xfrm_dev_state_flush() finds states under xfrm_state_dev_gc_lock, but drops the lock before calling xfrm_dev_state_free() because the driver callback may sleep. The device GC list does not hold an xfrm_state reference, so the state GC worker can destroy the same state concurrently.

The race can proceed as follows:

Both paths can invoke the driver callback and drop the device reference. CPU 0 can also access the xfrm_state after CPU 1 has freed it.

Serialize xfrm_state destruction against the deferred-device pass with a mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain the existing callback and device-reference release ordering.

Detalles técnicos trazas, registros y código del informe original
  CPU 0                               CPU 1
  find x on the device GC list
  drop xfrm_state_dev_gc_lock
  read x->xso.dev
                                      xfrm_state_gc_destroy(x)
                                      xfrm_dev_state_free(x)
                                      xfrm_state_free(x)
  continue xfrm_dev_state_free(x)

KASAN reported:

  BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0
  Read of size 8 at addr ffff88810bbaa960 by task poc/102

  Call Trace:
   xfrm_dev_state_free+0x24c/0x2a0
   xfrm_dev_state_flush+0x353/0x400
   xfrm_dev_event+0x26d/0x3a0
   notifier_call_chain+0xc0/0x280
   __dev_notify_flags+0x169/0x250
   netif_change_flags+0xe7/0x160
   dev_change_flags+0x96/0x220
   devinet_ioctl+0x7f4/0x1880

  Allocated by task 87:
   xfrm_state_alloc+0x1e/0x5c0
   xfrm_add_sa+0xe7f/0x5820
   xfrm_user_rcv_msg+0x4f3/0x940

  Freed by task 57:
   kmem_cache_free+0xcb/0x3d0
   xfrm_state_gc_task+0x4a8/0x650
   process_one_work+0x63a/0x1070

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98231",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d5f53edd43daf3e6e1633a49c561387f8f99e13f",
              "lessThan": "937108dc0258d6ac69926b00bc53598c98986ee1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "07b87f9eea0c30675084d50c82532d20168da009",
              "lessThan": "39e41af3653ee45c985190dd97426f318918d201",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "07b87f9eea0c30675084d50c82532d20168da009",
              "lessThan": "75fc4561772e2f9811abf39ed10443e6f4a4bc6c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "07b87f9eea0c30675084d50c82532d20168da009",
              "lessThan": "84e378395494963b1e581cf223a7cbeec8c0e2d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "07b87f9eea0c30675084d50c82532d20168da009",
              "lessThan": "89fefad9f971bc637fb22373078144f2563c4be9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8ecee44464a4926c9bef989a1490b7394785f584",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.44",
              "lessThan": "6.6.158",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.10.3",
              "lessThan": "6.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_state.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/xfrm/xfrm_state.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:10.540",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/39e41af3653ee45c985190dd97426f318918d201",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/75fc4561772e2f9811abf39ed10443e6f4a4bc6c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84e378395494963b1e581cf223a7cbeec8c0e2d6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89fefad9f971bc637fb22373078144f2563c4be9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/937108dc0258d6ac69926b00bc53598c98986ee1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: serialize state GC with device state flush\n\nThe deferred-device pass in xfrm_dev_state_flush() finds states under\nxfrm_state_dev_gc_lock, but drops the lock before calling\nxfrm_dev_state_free() because the driver callback may sleep.  The device\nGC list does not hold an xfrm_state reference, so the state GC worker can\ndestroy the same state concurrently.\n\nThe race can proceed as follows:\n\n  CPU 0                               CPU 1\n  find x on the device GC list\n  drop xfrm_state_dev_gc_lock\n  read x->xso.dev\n                                      xfrm_state_gc_destroy(x)\n                                      xfrm_dev_state_free(x)\n                                      xfrm_state_free(x)\n  continue xfrm_dev_state_free(x)\n\nBoth paths can invoke the driver callback and drop the device reference.\nCPU 0 can also access the xfrm_state after CPU 1 has freed it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0\n  Read of size 8 at addr ffff88810bbaa960 by task poc/102\n\n  Call Trace:\n   xfrm_dev_state_free+0x24c/0x2a0\n   xfrm_dev_state_flush+0x353/0x400\n   xfrm_dev_event+0x26d/0x3a0\n   notifier_call_chain+0xc0/0x280\n   __dev_notify_flags+0x169/0x250\n   netif_change_flags+0xe7/0x160\n   dev_change_flags+0x96/0x220\n   devinet_ioctl+0x7f4/0x1880\n\n  Allocated by task 87:\n   xfrm_state_alloc+0x1e/0x5c0\n   xfrm_add_sa+0xe7f/0x5820\n   xfrm_user_rcv_msg+0x4f3/0x940\n\n  Freed by task 57:\n   kmem_cache_free+0xcb/0x3d0\n   xfrm_state_gc_task+0x4a8/0x650\n   process_one_work+0x63a/0x1070\n\nSerialize xfrm_state destruction against the deferred-device pass with a\nmutex.  Keep xfrm_state_dev_gc_lock limited to list operations and retain\nthe existing callback and device-reference release ordering."
    }
  ],
  "lastModified": "2026-10-06T09:18:10.540",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}