CVE-2026-98370: xfrm: fix compat ALLOCSPI request use-after-free
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrmstatenetlink() builds the ALLOCSPI response with dumponestate(), which already calls alloccompat() with the response skb and header.
xfrmallocuserspi() then calls alloccompat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrmuserspiinfo as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's fraglist.
A multicast clone of the request shares skbsharedinfo and can observe that child. xfrmuserrcvmsg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat translation from dumponestate(), and no child is attached to the inbound request.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the use-after-free?
The affected path requires a compat ALLOCSPI request handled by the XFRM netlink code. The use-after-free arises when a multicast clone of the inbound request shares its skb data and a compat receiver is still copying the translated child when the request handler frees it.
Is the out-of-bounds read separate from the use-after-free?
Yes. The redundant compat conversion interprets a 228-byte compat xfrm_userspi_info as a 232-byte native structure, causing a four-byte read beyond the declared payload. It also attaches the translated child to the inbound request, creating the separate lifetime race that leads to use-after-free.
What does the fix change?
The fix removes the redundant conversion in xfrm_alloc_userspi(). The response retains the correct compat translation already performed by dump_one_state(), and no translated child is attached to the inbound request.