CVE-2026-98370 is a vulnerability in Linux Kernel
Published on October 6, 2026
xfrm: fix compat ALLOCSPI request use-after-free
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix compat ALLOCSPI request use-after-free
xfrm_state_netlink() builds the ALLOCSPI response with
dump_one_state(), which already calls alloc_compat() with the response
skb and header.
xfrm_alloc_userspi() then calls alloc_compat() again, but passes the
original request skb and its header. For a compat request, the
translator therefore interprets the 228-byte compat xfrm_userspi_info
as the 232-byte native layout and reads four bytes past the declared
payload. It also publishes the translated child through the request's
frag_list.
A multicast clone of the request shares skb_shared_info and can observe
that child. xfrm_user_rcv_msg() frees it after the request handler
returns, racing a compat receiver which may still be copying from it and
resulting in a use-after-free.
Remove the redundant conversion. The response keeps its correct compat
translation from dump_one_state(), and no child is attached to the
inbound request.
Products Associated with CVE-2026-98370
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below 17893987e52918c23945c42e47e894a936305a25 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below bb63ab52a18273ec68340ac49aebbaa7b514ccd5 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below 248433942155b42a0ef04a5806c8aca024ea7c33 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below e70f639aee2ff0def155c256cace9e0f81d998e2 is affected.
- Version 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 and below d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 is affected.
- Version 5.10 is affected.
- Before 5.10 is unaffected.
- Version 5.10.271, <= 5.10.* is unaffected.
- Version 5.15.222, <= 5.15.* is unaffected.
- Version 6.1.189, <= 6.1.* is unaffected.
- Version 6.6.158, <= 6.6.* is unaffected.
- Version 6.12.112, <= 6.12.* is unaffected.
- Version 6.18.54, <= 6.18.* is unaffected.
- Version 7.2.8, <= 7.2.* is unaffected.
- Version 7.3-rc4, <= * is unaffected.