CVE-2026-98370: fallo en Linux
xfrm: fix compat ALLOCSPI request use-after-free
Publicada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 0.2%
probabilidad de explotación
0.2%top 94% de las CVE
explotación observada
noninguna fuente lo reporta
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Productos afectados
Linux · LinuxCVEs relacionadas — Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-53197HIGHALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devicesEPSS 4.1%KEVCVE-2026-31431HIGHcrypto: algif_aead - Revert to operating out-of-placeEPSS 3.4%KEVCVE-2024-53104HIGHmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_formatEPSS 3.4%KEVCVE-2025-39682CRITICALtls: fix handling of zero-length records on the rx_listEPSS 2.9%KEVCVE-2024-36971HIGHnet: fix __dst_negative_advice() raceEPSS 2.7%KEVCVE-2024-53150HIGHALSA: usb-audio: Fix out of bounds reads when finding clock sourcesEPSS 1.4%KEV
Referencias
https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2