CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini()
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Fix work re-schedule after cancel in xfrmnatkeepalivenetfini()
After canceldelayedworksync() is called from xfrmnatkeepalivenetfini(), xfrmstatefini() flushes remaining states via xfrmstatedelete(), which calls xfrmnatkeepalivestateupdated() to re-schedule natkeepalivework.
The following is a simple race scenario:
cpu0 cpu1
cleanupnet() [Round 1] opsundolist() xfrmnetexit() xfrmnatkeepalivenetfini() canceldelayedworksync(natkeepalivework); xfrmstatefini() xfrmstateflush() xfrmstatedelete(x) xfrmstatedelete(x) xfrmnatkeepalivestateupdated(x) scheduledelayedwork(natkeepalivework); rcubarrier(); netcompletefree(); netpassivedec(net); llistadd(&net->deferfreelist, &deferfreelist);
cleanupnet() [Round 2] rcubarrier(); netcompletefree() kmemcachefree(netcachep, net); natkeepalivework() // on freed net
To prevent this, canceldelayedworksync() is replaced with disabledelayedworksync().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31406?
CVE-2026-31406 has a medium severity rating due to potential issues with the re-scheduling of work after cancellation.
How do I fix CVE-2026-31406?
To fix CVE-2026-31406, you should update your Linux kernel to the latest patched version.
What systems are affected by CVE-2026-31406?
CVE-2026-31406 affects the Linux kernel, specifically versions that implement the xfrm_nat_keepalive feature.
Is CVE-2026-31406 exploitable remotely?
CVE-2026-31406 does not appear to be directly exploitable remotely, but it may impact the stability of affected systems.
What are the consequences of not addressing CVE-2026-31406?
Not addressing CVE-2026-31406 may lead to unpredictable behavior and instability in applications utilizing the xfrm functionalities.