CVE-2026-68415
Received Received - Intake

Memory Corruption in Linux Kernel xfrm Subsystem

Vulnerability report for CVE-2026-68415, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: clear mode callbacks after failed mode setup xfrm_state_gc_task can run long after a failed IPTFS state setup. In the reproduced case, __xfrm_init_state() cached x->mode_cbs, IPTFS setup returned -ENOMEM before publishing mode_data, and the temporary module reference from xfrm_get_mode_cbs() was dropped immediately. The dead state then kept x->mode_cbs until deferred GC ran after xfrm_iptfs had been unloaded. Clear x->mode_cbs when mode init or clone fails before publishing mode_data. Those states never installed mode-specific state or the long-term IPTFS module pin, so deferred GC has nothing mode-specific to destroy and must not retain a callback table pointer past the temporary lookup reference. The buggy scenario involves two paths, with each column showing the order within that path: failed setup path: 1. cache x->mode_cbs 2. mode setup fails before mode_data 3. drop the temporary module ref 4. dead state keeps x->mode_cbs cached GC/unload path: 1. xfrm_state_put() queues GC work 2. xfrm_iptfs unloads later 3. xfrm_state_gc_task runs 4. GC dereferences stale x->mode_cbs This also covers the failed clone path where clone_state() returns before publishing mode_data. Validation reproduced this kernel report: Kernel panic - not syncing: Fatal exception CONFIG_FAULT_INJECTION_STACKTRACE_FILTER=y failslab_stacktrace_filter matched xfrm_iptfs frames ack_error=-12 FAULT_INJECTION: forcing a failure BUG: unable to handle page fault Workqueue: events xfrm_state_gc_task RIP: xfrm_state_gc_task+0x142/0x650 Modules linked in: esp4_offload xfrm_user [last unloaded: xfrm_iptfs] Kernel panic - not syncing: Fatal exception

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where a state cleanup task can access invalid memory after a failed state setup. When mode initialization fails before publishing data, the system incorrectly retains a callback table pointer. Later, when garbage collection runs, it dereferences this stale pointer, causing a kernel panic or crash.

Detection Guidance

This vulnerability is specific to the Linux kernel's xfrm subsystem and may not have direct network or system detection commands. Monitor kernel logs for xfrm_state_gc_task errors or kernel panics related to xfrm_iptfs. Check for failed IPTFS state setups or module unload issues.

Impact Analysis

This vulnerability can cause system crashes, kernel panics, or unexpected reboots. It may lead to denial of service if the kernel fails and requires manual intervention to recover. Systems using the affected kernel components could experience instability during state cleanup operations.

Mitigation Strategies

Update the Linux kernel to the patched version that resolves this issue. Avoid using IPTFS or ensure proper state cleanup during mode setup failures. Monitor kernel logs for xfrm-related errors.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-68415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart