CVE-2026-98231
Received Received - Intake

Race Condition in Linux Kernel XFRM State Handling

Vulnerability report for CVE-2026-98231, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: serialize state GC with device state flush The deferred-device pass in xfrm_dev_state_flush() finds states under xfrm_state_dev_gc_lock, but drops the lock before calling xfrm_dev_state_free() because the driver callback may sleep. The device GC list does not hold an xfrm_state reference, so the state GC worker can destroy the same state concurrently. The race can proceed as follows: CPU 0 CPU 1 find x on the device GC list drop xfrm_state_dev_gc_lock read x->xso.dev xfrm_state_gc_destroy(x) xfrm_dev_state_free(x) xfrm_state_free(x) continue xfrm_dev_state_free(x) Both paths can invoke the driver callback and drop the device reference. CPU 0 can also access the xfrm_state after CPU 1 has freed it. KASAN reported: BUG: KASAN: slab-use-after-free in xfrm_dev_state_free+0x24c/0x2a0 Read of size 8 at addr ffff88810bbaa960 by task poc/102 Call Trace: xfrm_dev_state_free+0x24c/0x2a0 xfrm_dev_state_flush+0x353/0x400 xfrm_dev_event+0x26d/0x3a0 notifier_call_chain+0xc0/0x280 __dev_notify_flags+0x169/0x250 netif_change_flags+0xe7/0x160 dev_change_flags+0x96/0x220 devinet_ioctl+0x7f4/0x1880 Allocated by task 87: xfrm_state_alloc+0x1e/0x5c0 xfrm_add_sa+0xe7f/0x5820 xfrm_user_rcv_msg+0x4f3/0x940 Freed by task 57: kmem_cache_free+0xcb/0x3d0 xfrm_state_gc_task+0x4a8/0x650 process_one_work+0x63a/0x1070 Serialize xfrm_state destruction against the deferred-device pass with a mutex. Keep xfrm_state_dev_gc_lock limited to list operations and retain the existing callback and device-reference release ordering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux d5f53edd43daf3e6e1633a49c561387f8f99e13f
Linux Linux 07b87f9eea0c30675084d50c82532d20168da009
Linux Linux 07b87f9eea0c30675084d50c82532d20168da009
Linux Linux 07b87f9eea0c30675084d50c82532d20168da009
Linux Linux 07b87f9eea0c30675084d50c82532d20168da009
Linux Linux 8ecee44464a4926c9bef989a1490b7394785f584
Linux Linux 6.6.44
Linux Linux 6.10.3
Linux Linux 6.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a race condition in the Linux kernel's xfrm (IPsec) subsystem. It occurs when the kernel tries to flush IPsec states while another process is destroying them. The vulnerability allows a use-after-free error where one CPU core accesses memory that another core has already freed, leading to potential crashes or privilege escalation.

Detection Guidance

This vulnerability is specific to the Linux kernel's xfrm subsystem and may not have direct detection commands. Monitor kernel logs for KASAN reports or slab-use-after-free errors related to xfrm_dev_state_free. Check for crashes or unusual behavior in network-related processes.

Impact Analysis

If exploited, this could crash the system or allow an attacker to execute arbitrary code with kernel privileges. It primarily affects systems using IPsec for network security, potentially disrupting secure communications or enabling unauthorized access to sensitive data.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If patches are unavailable, consider disabling the xfrm subsystem if not required. Monitor kernel updates from your distribution for fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98231. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart