๐Ÿ” CVE Alert

CVE-2026-92489

UNKNOWN 0.0

xfrm: Fix skb double-free in xfrm_dev_direct_output()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bfb9b9404a53a72524ce695551755117e9d3deb0 < 621871b696b108026bf4b44ed4085ffa2102f417 a0395e96831adee8ffa016bf958e4dce9ece656e < bc9297796bfdcc8d9609236e54519a4f38737aac 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 02deb637e965950148752a304dd1471212dd6470 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 2aed51fc58d9ce450e2c116efb956160fd06fa02 d1d673a5bede3767252cff19c0ab1e5387c6f43f 6.6.85 < 6.6.157 6.12.21 < 6.12.110 6.13.9 < 6.14
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/621871b696b108026bf4b44ed4085ffa2102f417 git.kernel.org: https://git.kernel.org/stable/c/bc9297796bfdcc8d9609236e54519a4f38737aac git.kernel.org: https://git.kernel.org/stable/c/02deb637e965950148752a304dd1471212dd6470 git.kernel.org: https://git.kernel.org/stable/c/56a347950e661c1a7f8f31c43a2ea53c2323b6f4 git.kernel.org: https://git.kernel.org/stable/c/2aed51fc58d9ce450e2c116efb956160fd06fa02