Sceawere

Vulnerability Detail

CVE-2026-98229UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel XFRM Use-After-Free

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: save input state data before secpath resets xfrm_input() stores the current xfrm_state in the skb secpath while it continues receive-side processing. Some input paths can reset that secpath before xfrm_input() has finished dereferencing the state. Receive callback users such as VTI and XFRM interfaces can reset the secpath. The VTI receive path does so before checking whether the packet crosses network namespaces, while the XFRM interface path does so only for cross-network-namespace packets. The XFRM_MAX_DEPTH error path can also reset the secpath before the final drop callback reports the current state's protocol. If secpath_reset() drops the last state reference while the state is concurrently deleted, xfrm_input() can still dereference the freed state when selecting transport_finish() or reporting the drop callback protocol. Save the state protocol on the stack while the state is still valid, and use the already saved address family for transport_finish(). A larval XFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This preserves the existing drop-path fallback while avoiding the post-reset state dereferences without adding an extra state reference to every received packet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-06T09:18:10.260Z",
  "pubdate": "2026-10-06T09:18:10.260Z",
  "executiveSummary": "This vulnerability is a Use-After-Free (UAF) flaw residing in the Linux kernel's XFRM (Transform) subsystem, specifically within the xfrm_input() function.\nThe issue arises due to race conditions during packet receive-side processing where the security path (secpath) is reset prematurely.\nAttackers capable of triggering specific network receive paths, such as VTI or XFRM interfaces, may exploit this race condition to reference memory that has already been deallocated.\nThe vulnerability allows for potential kernel memory corruption or arbitrary code execution, posing a significant risk to system stability and security.\nSuccessful exploitation requires the ability to influence kernel-level packet processing, typically necessitating local network access or the ability to inject crafted traffic to trigger the problematic code paths.\nThis vulnerability highlights a critical synchronization failure between packet transformation state management and secpath lifecycle handling.",
  "technicalDetails": "The root cause of this vulnerability is an improper synchronization mechanism in the xfrm_input() function regarding the lifecycle of the xfrm_state object. During the processing of incoming XFRM packets, the subsystem associates the current xfrm_state with the skb->sp (secpath) structure. However, certain code paths, such as the VTI interface receive path or the XFRM interface path, can trigger a call to secpath_reset() while xfrm_input() still requires access to the underlying state.\nThe secpath_reset() function effectively clears the secpath information, which can decrement the reference count of the xfrm_state to zero if no other references exist. If the state is concurrently deleted or finalized, the object is deallocated. Subsequently, xfrm_input() attempts to perform a dereference on this freed memory to either complete the transport_finish() call or to execute the drop callback reporting logic.\nThe attack flow initiates when a packet is processed through an interface that triggers the secpath reset condition. For instance, when a packet crosses network namespaces, the XFRM interface path may reset the secpath. If an attacker delivers a packet that forces a transition through the XFRM_MAX_DEPTH error path or triggers the VTI receive path, the race condition window opens. By timing the incoming packet sequence to coincide with an XFRM state deletion, the attacker ensures that the kernel pointer for the xfrm_state becomes a dangling pointer.\nExploitation involves manipulating kernel memory alignment and the allocator state to place malicious data or controlled structures at the memory address previously occupied by the freed xfrm_state. When the kernel continues execution in xfrm_input(), it performs operations based on the corrupted data (e.g., following a function pointer or a protocol type header), potentially redirecting control flow to attacker-controlled memory.\nThis flaw is persistent in the XFRM input path and affects the way nexthdr and protocol data are stored. Because the vulnerability involves the premature cleanup of kernel structures before completion of the processing lifecycle, it bypasses standard protocol enforcement. The fix involves offloading critical state data, such as the protocol identifier, onto the stack while the state object is still guaranteed to be valid, thereby preventing the need to access the potentially freed heap-allocated structure after the secpath has been cleared."
}
CVE-2026-98229: Linux Kernel XFRM Use-After-Free (HIGH Severity, CVSS: 7.8) | Sceawere