CVE-2026-98370: xfrm: fix compat ALLOCSPI request use-after-free

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix compat ALLOCSPI request use-after-free

xfrmstatenetlink() builds the ALLOCSPI response with dumponestate(), which already calls alloccompat() with the response skb and header.

xfrmallocuserspi() then calls alloccompat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrmuserspiinfo as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's fraglist.

A multicast clone of the request shares skbsharedinfo and can observe that child. xfrmuserrcvmsg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free.

Remove the redundant conversion. The response keeps its correct compat translation from dumponestate(), and no child is attached to the inbound request.

Affected Software

1 affected component
Linux Linux kernel

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required to trigger the use-after-free?

The affected path requires a compat ALLOCSPI request handled by the XFRM netlink code. The use-after-free arises when a multicast clone of the inbound request shares its skb data and a compat receiver is still copying the translated child when the request handler frees it.

2

Is the out-of-bounds read separate from the use-after-free?

Yes. The redundant compat conversion interprets a 228-byte compat xfrm_userspi_info as a 232-byte native structure, causing a four-byte read beyond the declared payload. It also attaches the translated child to the inbound request, creating the separate lifetime race that leads to use-after-free.

3

What does the fix change?

The fix removes the redundant conversion in xfrm_alloc_userspi(). The response retains the correct compat translation already performed by dump_one_state(), and no translated child is attached to the inbound request.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203