CVE-2026-98370 PUBLISHED

xfrm: fix compat ALLOCSPI request use-after-free

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix compat ALLOCSPI request use-after-free

xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header.

xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list.

A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free.

Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to 17893987e52918c23945c42e47e894a936305a25 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to bb63ab52a18273ec68340ac49aebbaa7b514ccd5 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to 248433942155b42a0ef04a5806c8aca024ea7c33 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to e70f639aee2ff0def155c256cace9e0f81d998e2 (excl.)
  • affected from 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 to d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.10 is affected
  • unaffected from 0 to 5.10 (excl.)
  • unaffected from 5.10.271 to 5.10.* (incl.)
  • unaffected from 5.15.222 to 5.15.* (incl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References