CVE-2026-31471: xfrm: iptfs: only publish mode_data after clone setup
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: only publish modedata after clone setup
iptfsclonestate() stores x->modedata before allocating the reorder window. If that allocation fails, the code frees the cloned state and returns -ENOMEM, leaving x->modedata pointing at freed memory.
The xfrm clone unwind later runs destroystate() through x->modedata, so the failed clone path tears down IPTFS state that clonestate() already freed.
Keep the cloned IPTFS state private until all allocations succeed so failed clones leave x->modedata unset. The destroy path already handles a NULL modedata pointer.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The supplied CVSS vector indicates local access is required, with low privileges and no user interaction. The vulnerability is not described as remotely exploitable.
What condition causes the unsafe cleanup path?
An IPTFS state clone must reach the point where its reorder-window allocation fails with -ENOMEM. In the vulnerable flow, the cloned state has already been published through mode_data, allowing later clone cleanup to destroy state that was already freed.
What is the potential security impact?
The severity is rated high with a 7.8 CVSS score. The vector rates confidentiality, integrity, and availability impact as high.