CVE-2026-64581
Received Received - Intake

Double-Free in Linux Kernel xfrm Subsystem

Vulnerability report for CVE-2026-64581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a double-free vulnerability in the Linux kernel's xfrm_user_policy() function. It occurs when a racing condition happens between a socket policy change and a data transmission on a UDP socket. The bug allows two threads to release the same memory reference twice, causing a use-after-free error that can crash the system or lead to privilege escalation.

Detection Guidance

This vulnerability involves a double-free in the Linux kernel's xfrm_user_policy function, specifically related to socket dst cache handling. Detection requires kernel-level inspection for race conditions in UDP socket operations. Check kernel logs for KASAN reports indicating slab-use-after-free in dst_release. Monitor for crashes or memory corruption during UDP socket operations, especially in network namespaces.

Impact Analysis

An unprivileged user in a user or network namespace could exploit this to crash the system, corrupt kernel memory, or potentially gain elevated privileges. The vulnerability affects connected UDP sockets during policy changes and data transmission.

Compliance Impact

This vulnerability does not directly impact compliance with standards like GDPR or HIPAA as it is a low-level kernel memory management issue affecting socket operations. Compliance risks would arise only if exploitation led to data breaches or unauthorized access, which is not described in the provided context.

Mitigation Strategies

Apply the kernel patch that replaces __sk_dst_reset with the atomic sk_dst_reset to prevent the double-free. Update to a fixed Linux kernel version where this issue is resolved. If immediate patching is not possible, restrict unprivileged access to network namespaces and UDP socket operations until the fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart