Skip to main content
Vulnerability Database/CVE-2026-98364

CVE-2026-98364: Linux Kernel XFRM Use-After-Free Vulnerability

CVE-2026-98364 is a use-after-free flaw in the Linux kernel XFRM subsystem that occurs during bundle creation when net_device references are improperly handled. This article covers the technical details, security impact, and remediation.

Published:

CVE-2026-98364 Overview

CVE-2026-98364 is a use-after-free vulnerability in the Linux kernel's IPsec transformation (xfrm) subsystem. The flaw resides in xfrm_bundle_create() and xfrm_create_dummy_bundle(), which read dst->dev into a local pointer without acquiring a device reference. A concurrent RTM_DELLINK netlink operation can replace dst->dev via dst_dev_put() and free the old net_device, leading to a stale pointer dereference inside xfrm6_fill_dst(). KASAN captured the condition as a slab-use-after-free at xfrm6_fill_dst+0x82c/0x860. The vulnerability has been resolved upstream by reading dst->dev via dst_dev_rcu() and extending the RCU read-side critical section until xfrm_fill_dst() has taken the required device references.

Critical Impact

A local attacker with network configuration privileges can trigger kernel memory corruption by racing xfrm bundle creation against RTM_DELLINK, potentially enabling privilege escalation or denial of service.

Affected Products

  • Linux kernel (upstream, prior to the fixing commits)
  • Linux kernel stable branches containing the vulnerable xfrm bundle creation logic
  • Distributions shipping affected kernels with IPv6 and IPsec (xfrm) enabled

Discovery Timeline

  • 2026-10-06 - CVE-2026-98364 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98364

Vulnerability Analysis

The Linux kernel's xfrm subsystem builds IPsec transformation bundles when a socket resolves a destination requiring policy processing. During bundle construction, xfrm_bundle_create() and xfrm_create_dummy_bundle() cache dst->dev in a local variable and pass it to xfrm_fill_dst() without holding a reference on the underlying net_device.

A concurrent RTM_DELLINK operation can invoke dst_dev_put(), which swaps dst->dev to the loopback device and releases the original net_device. If the free occurs between the local pointer read and the subsequent xfrm6_fill_dst() dereference, the kernel accesses freed slab memory through the stale pointer. KASAN confirms the condition with a slab-use-after-free report triggered through udpv6_sendmsg() → ip6_dst_lookup_flow() → xfrm_lookup_with_ifid() → xfrm_resolve_and_create_bundle().

Root Cause

The root cause is missing RCU protection around the read of dst->dev combined with the absence of a netdev_hold() reference before downstream consumers use the pointer. The xfrm bundle code assumed the device pointer remained valid for the duration of bundle construction, but RTM_DELLINK can concurrently replace and free it [CWE-416].

Attack Vector

Exploitation requires local access with privileges sufficient to issue RTM_DELLINK netlink messages (typically CAP_NET_ADMIN in a user namespace) and the ability to generate IPv6 traffic that triggers xfrm policy resolution. An attacker races the netlink link deletion against UDPv6 send operations to free the net_device while bundle creation holds a stale pointer to it.

The KASAN trace captured by upstream developers shows the use-after-free originating in xfrm6_fill_dst+0x82c/0x860 within net/ipv6/xfrm6_policy.c:86 during a netdev_hold() call on the already-freed device. See the upstream commits for the full patch set: kernel.org commit 8d85d6bc and kernel.org commit 9fa903b2.

Detection Methods for CVE-2026-98364

Indicators of Compromise

  • Kernel oops or KASAN reports referencing xfrm6_fill_dst, xfrm_resolve_and_create_bundle, or xfrm_bundle_create in dmesg or system journal
  • Unexpected kernel panics correlated with concurrent ip link delete activity and IPsec traffic
  • Processes with CAP_NET_ADMIN issuing high-frequency RTM_DELLINK netlink messages

Detection Strategies

  • Monitor kernel ring buffer for slab-use-after-free KASAN signatures involving xfrm or net_device structures
  • Audit netlink socket activity for unprivileged processes attempting link manipulation inside user namespaces
  • Alert on repeated kernel soft lockups or crashes on hosts running IPsec with IPv6 enabled

Monitoring Recommendations

  • Enable kernel audit rules for RTM_DELLINK netlink messages and correlate with IPsec policy use
  • Track running kernel build versions across the fleet to identify hosts missing the xfrm RCU fix
  • Forward kernel crash dumps and KASAN traces to a centralized log platform for pattern analysis

How to Mitigate CVE-2026-98364

Immediate Actions Required

  • Apply the upstream xfrm RCU fix or install the vendor kernel update that incorporates it
  • Restrict CAP_NET_ADMIN in user namespaces where untrusted workloads run, using seccomp or namespace policy
  • Reboot into the patched kernel; live-patching may not cover the fix depending on the distribution

Patch Information

The upstream fix reads dst->dev through dst_dev_rcu() and keeps the RCU read-side critical section active until xfrm_fill_dst() has taken the required device references. Review the patches at kernel.org commit 8d85d6bc and kernel.org commit 9fa903b2. Consult distribution security advisories for backported stable kernel releases.

Workarounds

  • Disable IPv6 xfrm policy processing on hosts that do not require IPsec over IPv6
  • Prevent unprivileged user namespace creation by setting kernel.unprivileged_userns_clone=0 where supported
  • Constrain containers from issuing netlink link administration via Linux Security Modules or runtime security policies

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.