CVE-2026-72463

Source
https://cve.org/CVERecord?id=CVE-2026-72463
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72463.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72463
Downstream
BELL (1)
DEBIAN (1)
SUSE (6)
UBUNTU (1)
Related
Published
2026-08-15T05:57:07Z
Modified
2026-10-08T02:51:48Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
xfrm: Fix dev use-after-free in xfrm async resumption
Details

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Fix dev use-after-free in xfrm async resumption

xfrm async resumption hold skb->dev refcnt until after transport_finish. However, xfrm_rcv_cb may modify skb->dev to tunnel dev without taking device reference, such as vti_rcv_cb. The subsequent async resumption will decrement the tunnel device's reference count, which lead to uaf of tunnel dev and refcnt leak of orig dev as below:

unregister_netdevice: waiting for vti1 to become free. Usage count = -2

Stash the original skb->dev to fix refcnt imbalance. The new skb->dev set by xfrm_rcv_cb can race with device teardown. Extend rcu protection over xfrm_rcv_cb and transport_finish to prevent races.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72463.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4236c30b437b80f673b9e08c8fae38b8d471ac9e
Fixed
fed4d3195a31125566876952ce66113ec1eb9008
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0f451b43c88bf2b9c038b414be580efee42e031b
Fixed
1acd93259b6be269e26be5d71c224bccd1f8352f
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1c428b03840094410c5fb6a5db30640486bbbfcb
Fixed
63a30015199912bd5055bead8001b1ae68a67cdb
Fixed
8045c0df98d4f14c54e5cb875f1c9c0ce89fe4ff
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.12.94
Fixed
6.12.112
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.18.23
Fixed
6.18.54
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6.19.13
Fixed
6.20
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5002beda5cac69d522dc54da0d5d463ed9c963d2

Affected versions

v6.*
v6.12.100
v6.12.101
v6.12.102
v6.12.103
v6.12.104
v6.12.105
v6.12.106
v6.12.107
v6.12.108
v6.12.109
v6.12.110
v6.12.111
v6.12.94
v6.12.95
v6.12.96
v6.12.97
v6.12.98
v6.12.99
v6.18.23
v6.18.24
v6.18.25
v6.18.26
v6.18.27
v6.18.28
v6.18.29
v6.18.30
v6.18.31
v6.18.32
v6.18.33
v6.18.34
v6.18.35
v6.18.36
v6.18.37
v6.18.38
v6.18.39
v6.18.40
v6.18.41
v6.18.42
v6.18.43
v6.18.44
v6.18.45
v6.18.46
v6.18.47
v6.18.48
v6.18.49
v6.18.50
v6.18.51
v6.18.52
v6.18.53
v6.19.13
v6.19.14

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72463.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72463.json"