CVE-2026-98370

high

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.

References

https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2

https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320

https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5

https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4

https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810

https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718

https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33

https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93355

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00172