๐Ÿ” CVE Alert

CVE-2026-98370

UNKNOWN 0.0

xfrm: fix compat ALLOCSPI request use-after-free

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < 17893987e52918c23945c42e47e894a936305a25 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < bb63ab52a18273ec68340ac49aebbaa7b514ccd5 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < 248433942155b42a0ef04a5806c8aca024ea7c33 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < e70f639aee2ff0def155c256cace9e0f81d998e2 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 < d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320
Linux / Linux
5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 git.kernel.org: https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25 git.kernel.org: https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 git.kernel.org: https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 git.kernel.org: https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5 git.kernel.org: https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33 git.kernel.org: https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2 git.kernel.org: https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320