CVE-2026-53197: xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: fix ABBA deadlock in iptfsdestroystate()
iptfsdestroystate() calls hrtimercancel() while holding a spinlock that the timer callback also acquires, leading to an ABBA deadlock on SMP systems.
For the output timer (iptfstimer): - iptfsdestroystate() holds x->lock, calls hrtimercancel() - iptfsdelaytimer() callback takes x->lock
For the drop timer (droptimer): - iptfsdestroystate() holds droplock, calls hrtimercancel() - iptfsdroptimer() callback takes droplock
Both timers use HRTIMERMODERELSOFT, so their callbacks run in softirq context. When hrtimercancel() is called for a soft timer that is currently executing on another CPU, hrtimercancelwaitrunning() spins on softirqexpirylock -- the same lock held by the softirq running the callback. If the callback is blocked waiting for the spinlock held by the caller of hrtimercancel(), a circular dependency forms:
CPU 0: holds lockA -> waits for softirqexpirylock CPU 1: holds softirqexpirylock -> waits for lockA
Fix by calling hrtimercancel() before acquiring the respective locks. hrtimercancel() is safe to call without holding any lock and will wait for any in-progress callback to complete. For the output timer, the lock is still acquired afterwards to drain the packet queue. For the drop timer, the lock/unlock pair is removed entirely since it only existed to serialize with the timer callback, which hrtimercancel() already guarantees.
Found by source code audit.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state() - Configuration
Fix ABBA deadlock by invoking hrtimer_cancel() for both soft timers (drop_timer and iptfs_timer) before acquiring the spinlock(s) that the corresponding timer callbacks take; in iptfs_destroy_state(), call hrtimer_cancel() while not holding the spinlock, then acquire locks only afterward to drain the packet queue.
Linux kernel xfrm/iptfs hrtimer_cancel() call ordering in iptfs_destroy_state() = Call hrtimer_cancel() before acquiring the respective spinlocks (remove lock/unlock pair that only serialized with the timer callback for the drop timer).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53197?
The severity of CVE-2026-53197 is rated at 22, indicating a significant risk associated with the vulnerability.
How can I fix CVE-2026-53197?
To fix CVE-2026-53197, update your Linux kernel to the version that contains the patch addressing the ABBA deadlock issue.
What systems are affected by CVE-2026-53197?
CVE-2026-53197 affects the Linux kernel, particularly on SMP systems where the deadlock scenario can occur.
What is the nature of the vulnerability in CVE-2026-53197?
CVE-2026-53197 pertains to an ABBA deadlock that occurs in the iptfs_destroy_state() function when hrtimer_cancel() is called while holding a spinlock.
When was CVE-2026-53197 published?
CVE-2026-53197 was published on June 25, 2026.