๐Ÿ” CVE Alert

CVE-2026-80848

UNKNOWN 0.0

xfrm: espintcp: fix UAF during close

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race condition during close for espintcp sockets: espintcp_close() frees emsg->skb via kfree_skb() without holding any socket lock. Concurrently, the xfrm_trans_reinject work queue invokes esp_output_tcp_finish() -> espintcp_push_skb() -> espintcp_push_msgs() -> skb_send_sock_locked(), which reads the same skb as a data source. Fix this by adding a synchronize_rcu() call after resetting sk_prot, since esp_output_tcp_finish() runs under RCU and won't use a socket with sk_prot == &tcp_prot. Simply taking the socket lock in espintcp_close() could lead to leaks, if esp_output_tcp_finish() re-adds an skb in the slot we just freed. After this, the existing barrier() is no longer needed.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 29121c5e6591da527e8e36ddac7120dc527f574d e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < ed5d9102190c45fc70121c036b0626b740040b75 e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 4bc0dfa28dca6fc0084203732695968049c44072 e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < ff8dd7a932f34409a56e1b91a1219340f17457e9 e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 4b31a875693c480c611519faca46216514e3e052 e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 24efebecf415ba264adba0f0491cec436463a14f e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < eb3bbf29c723fe75c0eb92be14f0ec92971fe272 e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < 54b41ad14da9a981131ab6e4d3f79321a503ea5d e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 < deb232e884877bf10b4ce2580909eedec986c284
Linux / Linux
5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/29121c5e6591da527e8e36ddac7120dc527f574d git.kernel.org: https://git.kernel.org/stable/c/ed5d9102190c45fc70121c036b0626b740040b75 git.kernel.org: https://git.kernel.org/stable/c/4bc0dfa28dca6fc0084203732695968049c44072 git.kernel.org: https://git.kernel.org/stable/c/ff8dd7a932f34409a56e1b91a1219340f17457e9 git.kernel.org: https://git.kernel.org/stable/c/4b31a875693c480c611519faca46216514e3e052 git.kernel.org: https://git.kernel.org/stable/c/24efebecf415ba264adba0f0491cec436463a14f git.kernel.org: https://git.kernel.org/stable/c/eb3bbf29c723fe75c0eb92be14f0ec92971fe272 git.kernel.org: https://git.kernel.org/stable/c/54b41ad14da9a981131ab6e4d3f79321a503ea5d git.kernel.org: https://git.kernel.org/stable/c/deb232e884877bf10b4ce2580909eedec986c284