Sceawere

Vulnerability Detail

CVE-2026-98241UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Linux Kernel IPv6 XFRM Type-Confusion

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Linux
Product
Linux
Attack Type
N/A
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it always pointed at a full IPv6 socket. That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb. The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request_sock allocation when they access inet_sock or ipv6_pinfo state. Resolve the owner with skb_to_full_sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb_to_full_sk().

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-06T09:18:12.090Z",
  "pubdate": "2026-10-06T09:18:12.090Z",
  "executiveSummary": "This vulnerability involves a type-confusion flaw within the Linux kernel's IPv6 XFRM (IPsec) subsystem, specifically residing in the local error-handling paths. The issue occurs when the kernel incorrectly treats a request_sock (mini-socket) as a full inet_sock or ipv6_pinfo structure when processing path MTU (PMTU) updates or error notifications.\nThe vulnerability affects kernel components responsible for IPv6 XFRM tunnel routing. An attacker capable of triggering specific network conditions—such as causing a reroute to an XFRM tunnel with a lower MTU while a TCP SYN-ACK is in the TCP_NEW_SYN_RECV state—can induce the kernel to perform out-of-bounds memory access.\nThe primary impact is a kernel-space memory corruption or information disclosure, which may lead to system instability, kernel panics (denial of service), or potential escalation of privileges depending on the surrounding memory layout. This vulnerability requires a specific network race condition involving request sockets, meaning it is not trivially exploitable but carries significant risk for high-performance networking stacks and security gateways using IPsec.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper handling of the skb->sk pointer within the xfrm6_local_rxpmtu() and xfrm6_local_error() functions. These functions assume that the socket associated with the sk_buff (skb) is always a fully initialized IPv6 socket (inet_sock). However, during the TCP three-way handshake, a TCP_NEW_SYN_RECV state utilizes a 'mini-socket' (request_sock) to manage connection metadata before a full socket is established.\nWhen a network packet hits a rerouting condition—specifically when selecting an IPv6 XFRM tunnel route with a lower MTU—the kernel invokes the aforementioned PMTU/error handling callbacks. If the skb is associated with a request_sock during this transition, the code performs a pointer cast that treats the smaller request_sock structure as if it were a significantly larger inet_sock or ipv6_pinfo structure.\nThe exploitation flow proceeds as follows: 1) An attacker initiates a TCP connection to a server utilizing IPv6 IPsec. 2) The server responds with a SYN-ACK, creating a request_sock. 3) The attacker triggers an ICMPv6 Packet Too Big (PTB) message or a routing change that forces the kernel to process an error path for the inflight SYN-ACK packet. 4) The kernel invokes xfrm6_local_rxpmtu() or xfrm6_local_error(), which retrieves the skb->sk. 5) Due to the lack of type verification, the function attempts to access members of the inet_sock structure, reading memory offset past the actual bounds of the request_sock allocation.\nThis out-of-bounds read can lead to the retrieval of sensitive kernel memory values into the packet processing path or, if the logic performs a write or complex dereference, cause a kernel panic due to invalid memory access or null pointer dereferencing within the struct members.\nThe vulnerability is present in the IPv6 XFRM subsystem where the assumption of 'full' socket ownership is enforced without validation via skb_to_full_sk(). By failing to bail out when a request_sock is detected, the kernel exposes its memory layout to unintended reads, violating the fundamental architectural separation between connection-request structures and active socket structures."
}
CVE-2026-98241: Linux Kernel IPv6 XFRM Type-Confusion (HIGH Severity, CVSS: 7.8) | Sceawere