Impact
The flaw arises from improper deletion of certain XFRM state lists in the Linux kernel. When a delete function is called more than once on the same object, the list node is first removed with a function that leaves a poisoned pointer, and the second deletion writes over that freed memory area. This corrupts kernel memory and, during a later traversal, causes a read use‑after‑free. The corrupted memory can be exploited to hijack execution flow, potentially allowing an attacker to run arbitrary code with kernel privileges.
Affected Systems
All Linux kernel releases that include the hlist structures for XFRM state lists but do not incorporate the fix in commit 14acf9652e56. The vulnerability applies to any kernel variant that uses the affected state_cache and state_cache_input lists before the corrected implementation.
Risk and Exploitability
No EPSS score or KEV entry is listed for this issue, indicating limited publicly known exploitation attempts. The vulnerability is a classic write use‑after‑free that can be leveraged if an attacker can cause repeated deletion of a state object, which typically requires privileged access to XFRM or some form of crafted IPsec traffic. Based on the description, the likely attack vector is a privileged or local attacker who can influence XFRM state handling, though a remote exploit through crafted network traffic cannot be ruled out without further evidence.
OpenCVE Enrichment