Description
In the Linux kernel, the following vulnerability has been resolved:

xfrm: use hlist_del_init_rcu for state_cache and state_cache_input

Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete") converted bydst/bysrc/byseq/byspi from
hlist_del_rcu() to hlist_del_init_rcu() so that a second
__xfrm_state_delete() on the same object becomes a no-op rather than a
write through LIST_POISON pprev. It missed state_cache and
state_cache_input, which kept hlist_del_rcu():

- hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so
hlist_unhashed() returns false.
- hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed()
returns true.

A second __xfrm_state_delete() therefore enters __hlist_del() on the
already-deleted state_cache/state_cache_input nodes and does
WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free
once the slab is reused. The corruption can in turn cause a subsequent
hlist_for_each_entry_rcu traversal to follow a dangling next pointer,
producing the read use-after-free reported in xfrm_input_state_lookup().

Switch state_cache and state_cache_input to hlist_del_init_rcu() to
match the other four lists, closing the write use-after-free and, with
it, the read use-after-free it spawns.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Write Use‑After‑Free leading to potential code execution
Action: Apply Kernel Patch
AI Analysis

Impact

The flaw arises from improper deletion of certain XFRM state lists in the Linux kernel. When a delete function is called more than once on the same object, the list node is first removed with a function that leaves a poisoned pointer, and the second deletion writes over that freed memory area. This corrupts kernel memory and, during a later traversal, causes a read use‑after‑free. The corrupted memory can be exploited to hijack execution flow, potentially allowing an attacker to run arbitrary code with kernel privileges.

Affected Systems

All Linux kernel releases that include the hlist structures for XFRM state lists but do not incorporate the fix in commit 14acf9652e56. The vulnerability applies to any kernel variant that uses the affected state_cache and state_cache_input lists before the corrected implementation.

Risk and Exploitability

No EPSS score or KEV entry is listed for this issue, indicating limited publicly known exploitation attempts. The vulnerability is a classic write use‑after‑free that can be leveraged if an attacker can cause repeated deletion of a state object, which typically requires privileged access to XFRM or some form of crafted IPsec traffic. Based on the description, the likely attack vector is a privileged or local attacker who can influence XFRM state handling, though a remote exploit through crafted network traffic cannot be ruled out without further evidence.

Generated by OpenCVE AI on October 6, 2026 at 12:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes commit 14acf9652e56, which replaces hlist_del_rcu with hlist_del_init_rcu for state_cache and state_cache_input.
  • Verify after updating that the kernel modules related to XFRM have been rebuilt with the new deletion routine and that no stale references remain.
  • If an immediate kernel upgrade is not feasible, limit or disable XFRM/IPsec functionality until the patch can be applied, and monitor system logs for unexpected crashes or memory corruption errors.

Generated by OpenCVE AI on October 6, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second __xfrm_state_delete() on the same object becomes a no-op rather than a write through LIST_POISON pprev. It missed state_cache and state_cache_input, which kept hlist_del_rcu(): - hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so hlist_unhashed() returns false. - hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed() returns true. A second __xfrm_state_delete() therefore enters __hlist_del() on the already-deleted state_cache/state_cache_input nodes and does WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlist_for_each_entry_rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm_input_state_lookup(). Switch state_cache and state_cache_input to hlist_del_init_rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.
Title xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:45:04.548Z

Reserved: 2026-09-25T10:25:14.328Z

Link: CVE-2026-98230

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:10.397

Modified: 2026-10-06T09:18:10.397

Link: CVE-2026-98230

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T12:15:15Z

Weaknesses