CVE-2026-98370

Source
https://cve.org/CVERecord?id=CVE-2026-98370
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98370.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98370
Downstream
Published
2026-10-06T08:46:54Z
Modified
2026-10-08T02:52:58Z
Summary
xfrm: fix compat ALLOCSPI request use-after-free
Details

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix compat ALLOCSPI request use-after-free

xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header.

xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list.

A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free.

Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98370.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3
Fixed
494f2bee9d8d0ebcfa249ac41bed7fed26d119b4
Fixed
17893987e52918c23945c42e47e894a936305a25
Fixed
42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810
Fixed
2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718
Fixed
bb63ab52a18273ec68340ac49aebbaa7b514ccd5
Fixed
248433942155b42a0ef04a5806c8aca024ea7c33
Fixed
e70f639aee2ff0def155c256cace9e0f81d998e2
Fixed
d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98370.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98370.json"