CVE-2026-92489
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfrm: Fix skb double-free in xfrm_dev_direct_output()
A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner.
Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bfb9b9404a53a72524ce695551755117e9d3deb0 < 621871b696b108026bf4b44ed4085ffa2102f417 | affected |
| Linux | Linux | a0395e96831adee8ffa016bf958e4dce9ece656e < bc9297796bfdcc8d9609236e54519a4f38737aac | affected |
| Linux | Linux | 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 02deb637e965950148752a304dd1471212dd6470 | affected |
| Linux | Linux | 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4 | affected |
| Linux | Linux | 5eddd76ec2fd1988f0a3450fde9730b10dd22992 < 2aed51fc58d9ce450e2c116efb956160fd06fa02 | affected |
| Linux | Linux | d1d673a5bede3767252cff19c0ab1e5387c6f43f | affected |
| Linux | Linux | 6.6.85 < 6.6.157 | affected |
| Linux | Linux | 6.12.21 < 6.12.110 | affected |
| Linux | Linux | 6.13.9 < 6.14 | affected |
| Linux | Linux | 6.14 | affected |
| Linux | Linux | 0 < 6.14 | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/621871b696b108026bf4b44ed4085ffa2102f417
- https://git.kernel.org/stable/c/bc9297796bfdcc8d9609236e54519a4f38737aac
- https://git.kernel.org/stable/c/02deb637e965950148752a304dd1471212dd6470
- https://git.kernel.org/stable/c/56a347950e661c1a7f8f31c43a2ea53c2323b6f4
- https://git.kernel.org/stable/c/2aed51fc58d9ce450e2c116efb956160fd06fa02
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.