CVE-2026-98230: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input
In the Linux kernel, the following vulnerability has been resolved:
xfrm: use hlistdelinitrcu for statecache and statecacheinput
Commit 14acf9652e56 ("xfrm: defensively unhash xfrmstate lists in xfrmstatedelete") converted bydst/bysrc/byseq/byspi from hlistdelrcu() to hlistdelinitrcu() so that a second xfrmstatedelete() on the same object becomes a no-op rather than a write through LISTPOISON pprev. It missed statecache and statecacheinput, which kept hlistdelrcu():
- hlistdelrcu() leaves pprev = LISTPOISON2 (non-NULL), so hlistunhashed() returns false. - hlistdelinitrcu() leaves pprev = NULL, so hlistunhashed() returns true.
A second xfrmstatedelete() therefore enters hlistdel() on the already-deleted statecache/statecacheinput nodes and does WRITEONCE(pprev, next) through LISTPOISON2 — a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlistforeachentryrcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrminputstatelookup().
Switch statecache and statecacheinput to hlistdelinitrcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.