๐Ÿ” CVE Alert

CVE-2026-98231

UNKNOWN 0.0

xfrm: serialize state GC with device state flush

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: serialize state GC with device state flush The deferred-device pass in xfrm_dev_state_flush() finds states under xfrm_state_dev_gc_lock, but drops the lock before calling xfrm_dev_state_free() because the driver callback may sleep. The device GC list does not hold an xfrm_state reference, so the state GC worker can destroy the same state concurrently. The race can proceed as follows: CPU 0 CPU 1 find x on the device GC list drop xfrm_state_dev_gc_lock read x->xso.dev xfrm_state_gc_destroy(x) xfrm_dev_state_free(x) xfrm_state_free(x) continue xfrm_dev_state_free(x) Both paths can invoke the driver callback and drop the device reference. CPU 0 can also access the xfrm_state after CPU 1 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0 Read of size 8 at addr ffff88810bbaa960 by task poc/102 Call Trace: xfrm_dev_state_free+0x24c/0x2a0 xfrm_dev_state_flush+0x353/0x400 xfrm_dev_event+0x26d/0x3a0 notifier_call_chain+0xc0/0x280 __dev_notify_flags+0x169/0x250 netif_change_flags+0xe7/0x160 dev_change_flags+0x96/0x220 devinet_ioctl+0x7f4/0x1880 Allocated by task 87: xfrm_state_alloc+0x1e/0x5c0 xfrm_add_sa+0xe7f/0x5820 xfrm_user_rcv_msg+0x4f3/0x940 Freed by task 57: kmem_cache_free+0xcb/0x3d0 xfrm_state_gc_task+0x4a8/0x650 process_one_work+0x63a/0x1070 Serialize xfrm_state destruction against the deferred-device pass with a mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain the existing callback and device-reference release ordering.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d5f53edd43daf3e6e1633a49c561387f8f99e13f < 937108dc0258d6ac69926b00bc53598c98986ee1 07b87f9eea0c30675084d50c82532d20168da009 < 39e41af3653ee45c985190dd97426f318918d201 07b87f9eea0c30675084d50c82532d20168da009 < 75fc4561772e2f9811abf39ed10443e6f4a4bc6c 07b87f9eea0c30675084d50c82532d20168da009 < 84e378395494963b1e581cf223a7cbeec8c0e2d6 07b87f9eea0c30675084d50c82532d20168da009 < 89fefad9f971bc637fb22373078144f2563c4be9 8ecee44464a4926c9bef989a1490b7394785f584 6.6.44 < 6.6.158 6.10.3 < 6.11
Linux / Linux
6.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/937108dc0258d6ac69926b00bc53598c98986ee1 git.kernel.org: https://git.kernel.org/stable/c/39e41af3653ee45c985190dd97426f318918d201 git.kernel.org: https://git.kernel.org/stable/c/75fc4561772e2f9811abf39ed10443e6f4a4bc6c git.kernel.org: https://git.kernel.org/stable/c/84e378395494963b1e581cf223a7cbeec8c0e2d6 git.kernel.org: https://git.kernel.org/stable/c/89fefad9f971bc637fb22373078144f2563c4be9