CVE-2026-43089: xfrm_user: fix info leak in build_mapping()
In the Linux kernel, the following vulnerability has been resolved:
xfrmuser: fix info leak in buildmapping()
struct xfrmusersaid has a one-byte padding hole after the proto field, which ends up never getting set to zero before copying out to userspace. Fix that up by zeroing out the whole structure before setting individual variables.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
Exploitation requires local access with low privileges. It does not require user interaction and is rated as low complexity.
What is the assessed security impact?
The CVSS vector rates the vulnerability as having high availability impact, with no confidentiality or integrity impact. The issue involves a one-byte uninitialized padding field being copied to userspace.
How is the issue addressed?
The fix zeroes the entire xfrm_usersa_id structure before setting its individual fields, preventing the padding byte from containing uninitialized data.