CVE-2026-98369
Received Received - Intake

RCU Use After Free in Linux Kernel XFRM Subsystem

Vulnerability report for CVE-2026-98369, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop include/net/addrconf.h:389 suspicious rcu_dereference_check() usage! Call Trace: __in6_dev_get_safely include/net/addrconf.h:389 [inline] ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620 ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651 xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806 process_one_work kernel/workqueue.c:3322 [inline] process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405 worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486 When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue, the reinjection loop ceased running in softirq context. Workqueue workers run in process context where local_bh_disable() does not enter an RCU read-side critical section under CONFIG_PREEMPT_RCU. Because finish callbacks (such as ip6_rcv_finish) expect to run under an RCU read lock (performing route lookups, l3mdev lookups, and accessing RCU-protected data structures), invoking them in workqueue context without rcu_read_lock() triggers RCU lockdep warnings. Furthermore, packets queued to the workqueue via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref). Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev with blackhole_netdev, so dst entries do not keep skb->dev alive while queued in the workqueue. Fix these issues by: 1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the caller's RCU section to ensure dst is reference-counted before queuing. 2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue deferral so skb->dev remains valid during finish() callback processing. 3. Acquiring rcu_read_lock() around the finish callback invocation loop in xfrm_trans_reinject().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
Linux Linux 7d98b26684cb2390729525b341ea099f0badbe18
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux 4f4920669d21e1060b7243e5118dc3b71ced1276
Linux Linux f520075da484306bbb8425afd2c42404ba74816f
Linux Linux 130d9e5017ade1b81d16783563edb38c12a2eab7
Linux Linux 5.15.75
Linux Linux 5.19.17
Linux Linux 6.0.3
Linux Linux 6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where the xfrm_trans_reinject function fails to properly handle RCU locks and device references when processing packets in workqueue context instead of softirq context. This causes RCU warnings and potential crashes due to missing rcu_read_lock(), skb_dst_force(), and dev_hold() calls.

Detection Guidance

This vulnerability is specific to the Linux kernel's xfrm subsystem and may trigger RCU lockdep warnings in kernel logs. Check for suspicious RCU usage warnings in system logs using commands like 'dmesg | grep -i "suspicious rcu usage"' or 'journalctl -k | grep -i "rcu"'. Monitor for kernel warnings related to xfrm_trans_reinject or ip6_pkt_drop.

Impact Analysis

This could lead to kernel crashes, data corruption, or denial of service if exploited. Systems using IPv6 with XFRM (IPsec) may experience instability or unexpected behavior during packet processing.

Mitigation Strategies

Apply the latest kernel patches that include the fix for this issue. Update your Linux kernel to a version containing the commit that adds rcu_read_lock(), skb_dst_force(), and dev_hold() for xfrm_trans_reinject. Monitor kernel logs for RCU warnings after applying updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98369. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart