๐Ÿ” CVE Alert

CVE-2026-72463

UNKNOWN 0.0

xfrm: Fix dev use-after-free in xfrm async resumption

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix dev use-after-free in xfrm async resumption xfrm async resumption hold skb->dev refcnt until after transport_finish. However, xfrm_rcv_cb may modify skb->dev to tunnel dev without taking device reference, such as vti_rcv_cb. The subsequent async resumption will decrement the tunnel device's reference count, which lead to uaf of tunnel dev and refcnt leak of orig dev as below: unregister_netdevice: waiting for vti1 to become free. Usage count = -2 Stash the original skb->dev to fix refcnt imbalance. The new skb->dev set by xfrm_rcv_cb can race with device teardown. Extend rcu protection over xfrm_rcv_cb and transport_finish to prevent races.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1c428b03840094410c5fb6a5db30640486bbbfcb < 63a30015199912bd5055bead8001b1ae68a67cdb 1c428b03840094410c5fb6a5db30640486bbbfcb < 8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff 4236c30b437b80f673b9e08c8fae38b8d471ac9e 0f451b43c88bf2b9c038b414be580efee42e031b 5002beda5cac69d522dc54da0d5d463ed9c963d2 6.12.94 < 6.13 6.18.23 < 6.19 6.19.13 < 6.20
Linux / Linux
7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/63a30015199912bd5055bead8001b1ae68a67cdb git.kernel.org: https://git.kernel.org/stable/c/8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff