CVE-2026-98241: ipv6: xfrm: use full sockets in local error paths
In the Linux kernel, the following vulnerability has been resolved:
ipv6: xfrm: use full sockets in local error paths
xfrm6localrxpmtu() and xfrm6localerror() dereference skb->sk as if it always pointed at a full IPv6 socket.
That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCPNEWSYNRECV requestsock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb.
The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the requestsock allocation when they access inetsock or ipv6pinfo state.
Resolve the owner with skbtofullsk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skbtofullsk().