CVE-2026-53197: xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()

Published Jun 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: fix ABBA deadlock in iptfsdestroystate()

iptfsdestroystate() calls hrtimercancel() while holding a spinlock that the timer callback also acquires, leading to an ABBA deadlock on SMP systems.

For the output timer (iptfstimer): - iptfsdestroystate() holds x->lock, calls hrtimercancel() - iptfsdelaytimer() callback takes x->lock

For the drop timer (droptimer): - iptfsdestroystate() holds droplock, calls hrtimercancel() - iptfsdroptimer() callback takes droplock

Both timers use HRTIMERMODERELSOFT, so their callbacks run in softirq context. When hrtimercancel() is called for a soft timer that is currently executing on another CPU, hrtimercancelwaitrunning() spins on softirqexpirylock -- the same lock held by the softirq running the callback. If the callback is blocked waiting for the spinlock held by the caller of hrtimercancel(), a circular dependency forms:

CPU 0: holds lockA -> waits for softirqexpirylock CPU 1: holds softirqexpirylock -> waits for lockA

Fix by calling hrtimercancel() before acquiring the respective locks. hrtimercancel() is safe to call without holding any lock and will wait for any in-progress callback to complete. For the output timer, the lock is still acquired afterwards to drain the packet queue. For the drop timer, the lock/unlock pair is removed entirely since it only existed to serialize with the timer callback, which hrtimercancel() already guarantees.

Found by source code audit.

Affected Software

10 affected components
Linux Linux kernel
Linux Linux kernel>=6.14<6.18.36
Linux Linux kernel>=6.19<7.0.13
Linux Linux kernel=7.1-rc1
Linux Linux kernel=7.1-rc2
Linux Linux kernel=7.1-rc3
Linux Linux kernel=7.1-rc4
Linux Linux kernel=7.1-rc5
Linux Linux kernel=7.1-rc6
Linux Linux kernel=7.1-rc7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
  2. Configuration

    Fix ABBA deadlock by invoking hrtimer_cancel() for both soft timers (drop_timer and iptfs_timer) before acquiring the spinlock(s) that the corresponding timer callbacks take; in iptfs_destroy_state(), call hrtimer_cancel() while not holding the spinlock, then acquire locks only afterward to drain the packet queue.

    Linux kernel xfrm/iptfs hrtimer_cancel() call ordering in iptfs_destroy_state() = Call hrtimer_cancel() before acquiring the respective spinlocks (remove lock/unlock pair that only serialized with the timer callback for the drop timer).

Event History

Jun 25, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
Description
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-53197?

The severity of CVE-2026-53197 is rated at 22, indicating a significant risk associated with the vulnerability.

2

How can I fix CVE-2026-53197?

To fix CVE-2026-53197, update your Linux kernel to the version that contains the patch addressing the ABBA deadlock issue.

3

What systems are affected by CVE-2026-53197?

CVE-2026-53197 affects the Linux kernel, particularly on SMP systems where the deadlock scenario can occur.

4

What is the nature of the vulnerability in CVE-2026-53197?

CVE-2026-53197 pertains to an ABBA deadlock that occurs in the iptfs_destroy_state() function when hrtimer_cancel() is called while holding a spinlock.

5

When was CVE-2026-53197 published?

CVE-2026-53197 was published on June 25, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203