Sceawere

Vulnerability Detail

CVE-2026-98230UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel XFRM State Use-After-Free

Vulnerability Metadata

Severity
High
Score / CVSS
7
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second __xfrm_state_delete() on the same object becomes a no-op rather than a write through LIST_POISON pprev. It missed state_cache and state_cache_input, which kept hlist_del_rcu(): - hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so hlist_unhashed() returns false. - hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed() returns true. A second __xfrm_state_delete() therefore enters __hlist_del() on the already-deleted state_cache/state_cache_input nodes and does WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlist_for_each_entry_rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm_input_state_lookup(). Switch state_cache and state_cache_input to hlist_del_init_rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.0",
  "pubDate": "2026-10-06T09:18:10.397Z",
  "pubdate": "2026-10-06T09:18:10.397Z",
  "executiveSummary": "This vulnerability is a use-after-free (UAF) flaw residing in the Linux kernel's XFRM (Transform) subsystem, specifically within state cache management.\nThe issue stems from improper synchronization and node unlinking logic in __xfrm_state_delete(), leading to memory corruption when deleting XFRM states.\nAn attacker capable of triggering multiple deletion attempts on the same XFRM state object can induce a write-after-free, followed by a read-after-free during subsequent RCU-protected hlist traversals.\nThe vulnerability affects kernel memory integrity and may lead to system crashes or potential arbitrary code execution by leveraging stale pointers in the slab allocator.\nSuccessful exploitation requires the ability to perform operations that invoke XFRM state deletion, typically requiring local access to network namespaces where XFRM policies can be manipulated.\nThe risk is categorized as high, as it impacts core networking infrastructure and can lead to local privilege escalation or kernel-level denial-of-service.",
  "technicalDetails": "The root cause of this vulnerability is the use of hlist_del_rcu() instead of hlist_del_init_rcu() within the __xfrm_state_delete() function for the state_cache and state_cache_input lists.\nIn the Linux kernel, hlist_del_rcu() removes an element from an hlist but leaves the pprev pointer set to LIST_POISON2. This causes hlist_unhashed() to return false, incorrectly indicating that the node is still part of a list.\nWhen __xfrm_state_delete() is called twice on the same object, the kernel attempts to perform list removal again. Because hlist_unhashed() evaluates to false, the kernel proceeds to execute __hlist_del().\nThis operation performs a WRITE_ONCE(*pprev, next) instruction. Since pprev points to LIST_POISON2, the kernel writes to an invalid memory location. If the underlying slab has been reallocated by this point, this constitutes a write use-after-free, resulting in heap memory corruption.\nThe corruption of the hlist structure propagates to subsequent operations. When xfrm_input_state_lookup() executes an hlist_for_each_entry_rcu() traversal, it encounters the corrupted, dangling next pointer. This triggers a read use-after-free as the kernel attempts to dereference the corrupted pointer during the list walk.\nThe vulnerable components are specifically the state_cache and state_cache_input lists within the XFRM subsystem. By design, these lists are intended to be managed via RCU (Read-Copy-Update) primitives to ensure safe concurrent access.\nExploitation involves an attacker inducing race conditions or triggered path execution that causes redundant calls to the deletion logic. By forcing the kernel to reuse the memory associated with a 'deleted' XFRM state before the RCU grace period concludes, the attacker can influence the state of the list pointers to gain control over memory read/write primitives.\nThe impact includes kernel panic, memory disclosure via the read UAF, or system compromise if the write UAF is used to overwrite critical kernel objects or function pointers."
}
CVE-2026-98230: Linux Kernel XFRM State Use-After-Free (HIGH Severity, CVSS: 7.0) | Sceawere