Description
In the Linux kernel, the following vulnerability has been resolved:

xfrm: serialize state GC with device state flush

The deferred-device pass in xfrm_dev_state_flush() finds states under
xfrm_state_dev_gc_lock, but drops the lock before calling
xfrm_dev_state_free() because the driver callback may sleep. The device
GC list does not hold an xfrm_state reference, so the state GC worker can
destroy the same state concurrently.

The race can proceed as follows:

CPU 0 CPU 1
find x on the device GC list
drop xfrm_state_dev_gc_lock
read x->xso.dev
xfrm_state_gc_destroy(x)
xfrm_dev_state_free(x)
xfrm_state_free(x)
continue xfrm_dev_state_free(x)

Both paths can invoke the driver callback and drop the device reference.
CPU 0 can also access the xfrm_state after CPU 1 has freed it.

KASAN reported:

BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0
Read of size 8 at addr ffff88810bbaa960 by task poc/102

Call Trace:
xfrm_dev_state_free+0x24c/0x2a0
xfrm_dev_state_flush+0x353/0x400
xfrm_dev_event+0x26d/0x3a0
notifier_call_chain+0xc0/0x280
__dev_notify_flags+0x169/0x250
netif_change_flags+0xe7/0x160
dev_change_flags+0x96/0x220
devinet_ioctl+0x7f4/0x1880

Allocated by task 87:
xfrm_state_alloc+0x1e/0x5c0
xfrm_add_sa+0xe7f/0x5820
xfrm_user_rcv_msg+0x4f3/0x940

Freed by task 57:
kmem_cache_free+0xcb/0x3d0
xfrm_state_gc_task+0x4a8/0x650
process_one_work+0x63a/0x1070

Serialize xfrm_state destruction against the deferred-device pass with a
mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain
the existing callback and device-reference release ordering.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Kernel Use‑After‑Free memory corruption
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a race condition in the Linux kernel's xfrm state management that can lead to a use‑after‑free of an xfrm_state object. During a device state flush, the code releases a lock before calling a driver callback that may sleep, allowing the garbage collector to free the same state concurrently. The resulting double free can corrupt kernel memory and potentially crash the system or allow an attacker to execute arbitrary code if they can trigger the race.

Affected Systems

The flaw affects the Linux kernel across all versions that implement the xfrm state device cleanup routine, as described in the kernel source. No specific versioning is provided, so any kernel build containing the xfrm code before the patch is potentially vulnerable. The vendor identifier is Linux:Linux, referencing the open‑source Linux kernel.

Risk and Exploitability

The Common Vulnerability Scoring System (CVSS) value is not available, and the exploit probability score (EPSS) is not provided; the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Nevertheless, a use‑after‑free in kernel code is a high‑risk flaw that can lead to denial of service or remote code execution if an attacker can trigger the race. The attack vector likely requires local privileges or the ability to manipulate kernel networking state, but absence of public exploits makes the realistic risk uncertain.

Generated by OpenCVE AI on October 6, 2026 at 12:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that serializes xfrm_state destruction against the device state flush. Update the kernel to a version that includes the upstream fix.
  • If an immediate kernel update is not feasible, disable the IPsec/xfrm state handling features that rely on the vulnerable code path to reduce exposure, or limit administrative access to the affected networking components.
  • Monitor system logs for KASAN errors mentioning xfrm_dev_state_free, and perform kernel debugging to confirm that the race no longer occurs.

Generated by OpenCVE AI on October 6, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: xfrm: serialize state GC with device state flush The deferred-device pass in xfrm_dev_state_flush() finds states under xfrm_state_dev_gc_lock, but drops the lock before calling xfrm_dev_state_free() because the driver callback may sleep. The device GC list does not hold an xfrm_state reference, so the state GC worker can destroy the same state concurrently. The race can proceed as follows: CPU 0 CPU 1 find x on the device GC list drop xfrm_state_dev_gc_lock read x->xso.dev xfrm_state_gc_destroy(x) xfrm_dev_state_free(x) xfrm_state_free(x) continue xfrm_dev_state_free(x) Both paths can invoke the driver callback and drop the device reference. CPU 0 can also access the xfrm_state after CPU 1 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0 Read of size 8 at addr ffff88810bbaa960 by task poc/102 Call Trace: xfrm_dev_state_free+0x24c/0x2a0 xfrm_dev_state_flush+0x353/0x400 xfrm_dev_event+0x26d/0x3a0 notifier_call_chain+0xc0/0x280 __dev_notify_flags+0x169/0x250 netif_change_flags+0xe7/0x160 dev_change_flags+0x96/0x220 devinet_ioctl+0x7f4/0x1880 Allocated by task 87: xfrm_state_alloc+0x1e/0x5c0 xfrm_add_sa+0xe7f/0x5820 xfrm_user_rcv_msg+0x4f3/0x940 Freed by task 57: kmem_cache_free+0xcb/0x3d0 xfrm_state_gc_task+0x4a8/0x650 process_one_work+0x63a/0x1070 Serialize xfrm_state destruction against the deferred-device pass with a mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain the existing callback and device-reference release ordering.
Title xfrm: serialize state GC with device state flush
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:45:05.183Z

Reserved: 2026-09-25T10:25:14.328Z

Link: CVE-2026-98231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:10.540

Modified: 2026-10-06T09:18:10.540

Link: CVE-2026-98231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T12:15:15Z

Weaknesses