๐Ÿ” CVE Alert

CVE-2026-98230

UNKNOWN 0.0

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second __xfrm_state_delete() on the same object becomes a no-op rather than a write through LIST_POISON pprev. It missed state_cache and state_cache_input, which kept hlist_del_rcu(): - hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so hlist_unhashed() returns false. - hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed() returns true. A second __xfrm_state_delete() therefore enters __hlist_del() on the already-deleted state_cache/state_cache_input nodes and does WRITE_ONCE(*pprev, next) through LIST_POISON2 โ€” a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlist_for_each_entry_rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm_input_state_lookup(). Switch state_cache and state_cache_input to hlist_del_init_rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
aa48a18fdb0911572d133057cd579db704b87da4 < fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5 0045e3d80613cc7174dc15f189ee6fc4e73b9365 < 4748c27e2e6a1969e02f1df46e62f79d2799b80b 0045e3d80613cc7174dc15f189ee6fc4e73b9365 < 9b74a47a4cbd0d29faff4f3b199212c73e6b6220 0045e3d80613cc7174dc15f189ee6fc4e73b9365 < 2afb8dc1f4390f164db8352f8e685e126e9db566 5e4334dc39443645415450163ff5ff1ee7e79784 6.12.13 < 6.12.112
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5 git.kernel.org: https://git.kernel.org/stable/c/4748c27e2e6a1969e02f1df46e62f79d2799b80b git.kernel.org: https://git.kernel.org/stable/c/9b74a47a4cbd0d29faff4f3b199212c73e6b6220 git.kernel.org: https://git.kernel.org/stable/c/2afb8dc1f4390f164db8352f8e685e126e9db566