Description
In the Linux kernel, the following vulnerability has been resolved:

xfrm: Fix skb double-free in xfrm_dev_direct_output()

A return value other than 1 from local_out() means that the skb has been
consumed or its ownership was transferred. xfrm_dev_direct_output()
nevertheless frees the skb on this path, causing a double-free when
netfilter drops the packet and invalidating any other owner.

Return the local_out() result directly, matching the ownership handling
in xfrm_output_resume().
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel allows a double free of a network buffer, or skb, within the xfrm_dev_direct_output function. When the local_out function returns a code other than 1, the skb is considered consumed or ownership has been transferred. However, xfrm_dev_direct_output still frees the skb, resulting in a double free. This bug can corrupt kernel memory, and it is inferred that this could lead to arbitrary code execution or a kernel crash, as the freed memory may be reused for malicious data or used by other kernel structures.

Affected Systems

Linux kernels of all versions prior to the patch that addresses this bug are affected. The vendor is Linux, and the product is the Linux kernel. The exact version range is not specified in the CVE data, so all builds before the incorporated patch commit (e.g., 02deb637e965950148752a304dd1471212dd6470) remain vulnerable.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that, while the risk is severe, the likelihood of exploitation at this time is low. The vulnerability is not marked in the CISA KEV catalog. Based on the description, it is inferred that exploitation would most likely occur via crafted network traffic that forces local_out to return a non-1 status, thereby triggering the double free path in xfrm_dev_direct_output. Because the flaw is kernel-level, successful exploitation could lead to privilege escalation or complete system compromise.

Generated by OpenCVE AI on September 19, 2026 at 16:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch affecting xfrm_dev_direct_output, such as the commit identified in the references (e.g., 02deb637e965950148752a304dd1471212dd6470).
  • If an immediate kernel upgrade is infeasible, temporarily restrict or filter traffic that can invoke xfrm_dev_direct_output, for example by using netfilter or iptables rules to block suspicious packets or unnecessary IPsec traffic until a patch is applied.
  • Ensure that the kernel memory allocator is configured securely, and consider enabling kernel hardening features such as KASLR and CONFIG_SLUB_DEBUG, which can help mitigate the impact of memory corruption bugs, though they do not replace the need for the specific patch.

Generated by OpenCVE AI on September 19, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
Title xfrm: Fix skb double-free in xfrm_dev_direct_output()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:28.166Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.007

Modified: 2026-09-18T18:18:13.037

Link: CVE-2026-92489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses