CVE-2026-98372: xfrm: iptfs: fix stack OOB read in iptfs_skb_reset_frag_walk()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: fix stack OOB read in iptfsskbresetfragwalk()

iptfsskbresetfragwalk() advances to the fragment containing @offset with an unbounded loop:

while (offset >= walk->past + walk->frags[walk->fragi].len) walk->past += walk->frags[walk->fragi++].len;

walk->fragi is advanced and walk->frags[walk->fragi] is dereferenced without ever checking fragi against walk->nrfrags. When the requested offset is at or beyond the total length spanned by the walk's fragments, fragi runs past nrfrags and off the end of the fixed-size on-stack frags[MAXSKBFRAGS + 1] array, reading out-of-bounds stack memory.

The two callers behave differently: iptfsskbaddfrags() already guards against this with

if (!walk->nrfrags || offset >= walk->total + walk->initialoffset) return len;

but iptfsskbcanaddfrags() has no such guard and calls iptfsskbresetfragwalk() unconditionally, so it performs the out-of-range walk. Its own "fragi < walk->nrfrags" bound check runs only afterwards, too late to prevent the read.

This is reachable from the receive path: a crafted IP-TFS (AGGFRAG) payload delivered to an IPTFS SA drives iptfsreassemcont() -> iptfsskbcanaddfrags() with an offset past the fragment total, e.g.:

BUG: KASAN: stack-out-of-bounds in iptfsskbresetfragwalk+0x235/0x250 Read of size 4 at addr ffff888008ad7210 by task repro/345 iptfsskbresetfragwalk+0x235/0x250 net/xfrm/xfrmiptfs.c:392 iptfsskbcanaddfrags+0x155/0x310 net/xfrm/xfrmiptfs.c:420 iptfsreassemcont+0xcf8/0x1140 net/xfrm/xfrmiptfs.c:902 iptfsinputordered+0x552/0x670 net/xfrm/xfrmiptfs.c:1280 iptfsinput+0x3d6/0xde0 net/xfrm/xfrmiptfs.c:1741 xfrminput+0x282f/0x6140 net/xfrm/xfrminput.c:700 xfrm4esprcv+0x93/0x120 net/ipv4/xfrm4protocol.c:104 iprcv+0x278/0x2d0 net/ipv4/ipinput.c:612

Give iptfsskbcanaddfrags() the same up-front guard that iptfsskbaddfrags() already has, so the walk is never entered with an out-of-range offset. When it triggers, the caller falls back to the existing linearize-and-copy path, which is safe.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Add the same up-front bounds guard used by iptfs_skb_add_frags() to iptfs_skb_can_add_frags(): if (!walk->nr_frags || offset >= walk->total + walk->initial_offset) return len; This prevents iptfs_skb_reset_frag_walk() from being called with an out-of-range offset.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Frequently Asked Questions

1

Which systems are exposed to the reachable receive-path condition?

Systems using an IPTFS security association (SA) are in scope. The issue is reachable when a crafted IP-TFS AGGFRAG payload is delivered to that IPTFS SA.

2

What input condition triggers the out-of-bounds read?

The fragment-walk offset must be at or beyond the total length covered by the walk's fragments. In the affected caller, the fragment index is advanced past the fragment count and the fixed-size on-stack fragment array is then read out of bounds.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203