← All Advisories

Linux Kernel xfrm Input State Pointer Dereferenced After VTI/XFRM Interface Resets the Security Path, Yielding a Use-After-Free

Last refreshed2026-10-10

Status: UPDATED  |  Advisory ID: CVE-2026-98229

Key Details

CVECVE-2026-98229
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

xfrm: save input state data before secpath resets

xfrm_input() stores the current xfrm_state in the skb secpath while it

continues receive-side processing. Some input paths can reset that secpath

before xfrm_input() has finished dereferencing the state.

Receive callback users such as VTI and XFRM interfaces can reset the

secpath. The VTI receive path does so before checking whether the packet

crosses network namespaces, while the XFRM interface path does so only for

cross-network-namespace packets. The XFRM_MAX_DEPTH error path can also

reset the secpath before the final drop callback reports the current

state's protocol.

If secpath_reset() drops the last state reference while the state is

concurrently deleted, xfrm_input() can still dereference the freed state

when selecting transport_finish() or reporting the drop callback protocol.

Save the state protocol on the stack while the state is still valid,

and use the already saved address family for transport_finish(). A larval

XFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This

preserves the existing drop-path fallback while avoiding the post-reset

state dereferences without adding an extra state reference to every

received packet. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98229
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98229