CVE-2026-98364 Overview
CVE-2026-98364 is a use-after-free vulnerability in the Linux kernel's IPsec transformation (xfrm) subsystem. The flaw resides in xfrm_bundle_create() and xfrm_create_dummy_bundle(), which read dst->dev into a local pointer without acquiring a device reference. A concurrent RTM_DELLINK netlink operation can replace dst->dev via dst_dev_put() and free the old net_device, leading to a stale pointer dereference inside xfrm6_fill_dst(). KASAN captured the condition as a slab-use-after-free at xfrm6_fill_dst+0x82c/0x860. The vulnerability has been resolved upstream by reading dst->dev via dst_dev_rcu() and extending the RCU read-side critical section until xfrm_fill_dst() has taken the required device references.
Critical Impact
A local attacker with network configuration privileges can trigger kernel memory corruption by racing xfrm bundle creation against RTM_DELLINK, potentially enabling privilege escalation or denial of service.
Affected Products
- Linux kernel (upstream, prior to the fixing commits)
- Linux kernel stable branches containing the vulnerable xfrm bundle creation logic
- Distributions shipping affected kernels with IPv6 and IPsec (xfrm) enabled
Discovery Timeline
- 2026-10-06 - CVE-2026-98364 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98364
Vulnerability Analysis
The Linux kernel's xfrm subsystem builds IPsec transformation bundles when a socket resolves a destination requiring policy processing. During bundle construction, xfrm_bundle_create() and xfrm_create_dummy_bundle() cache dst->dev in a local variable and pass it to xfrm_fill_dst() without holding a reference on the underlying net_device.
A concurrent RTM_DELLINK operation can invoke dst_dev_put(), which swaps dst->dev to the loopback device and releases the original net_device. If the free occurs between the local pointer read and the subsequent xfrm6_fill_dst() dereference, the kernel accesses freed slab memory through the stale pointer. KASAN confirms the condition with a slab-use-after-free report triggered through udpv6_sendmsg() → ip6_dst_lookup_flow() → xfrm_lookup_with_ifid() → xfrm_resolve_and_create_bundle().
Root Cause
The root cause is missing RCU protection around the read of dst->dev combined with the absence of a netdev_hold() reference before downstream consumers use the pointer. The xfrm bundle code assumed the device pointer remained valid for the duration of bundle construction, but RTM_DELLINK can concurrently replace and free it [CWE-416].
Attack Vector
Exploitation requires local access with privileges sufficient to issue RTM_DELLINK netlink messages (typically CAP_NET_ADMIN in a user namespace) and the ability to generate IPv6 traffic that triggers xfrm policy resolution. An attacker races the netlink link deletion against UDPv6 send operations to free the net_device while bundle creation holds a stale pointer to it.
The KASAN trace captured by upstream developers shows the use-after-free originating in xfrm6_fill_dst+0x82c/0x860 within net/ipv6/xfrm6_policy.c:86 during a netdev_hold() call on the already-freed device. See the upstream commits for the full patch set: kernel.org commit 8d85d6bc and kernel.org commit 9fa903b2.
Detection Methods for CVE-2026-98364
Indicators of Compromise
- Kernel oops or KASAN reports referencing xfrm6_fill_dst, xfrm_resolve_and_create_bundle, or xfrm_bundle_create in dmesg or system journal
- Unexpected kernel panics correlated with concurrent ip link delete activity and IPsec traffic
- Processes with CAP_NET_ADMIN issuing high-frequency RTM_DELLINK netlink messages
Detection Strategies
- Monitor kernel ring buffer for slab-use-after-free KASAN signatures involving xfrm or net_device structures
- Audit netlink socket activity for unprivileged processes attempting link manipulation inside user namespaces
- Alert on repeated kernel soft lockups or crashes on hosts running IPsec with IPv6 enabled
Monitoring Recommendations
- Enable kernel audit rules for RTM_DELLINK netlink messages and correlate with IPsec policy use
- Track running kernel build versions across the fleet to identify hosts missing the xfrm RCU fix
- Forward kernel crash dumps and KASAN traces to a centralized log platform for pattern analysis
How to Mitigate CVE-2026-98364
Immediate Actions Required
- Apply the upstream xfrm RCU fix or install the vendor kernel update that incorporates it
- Restrict CAP_NET_ADMIN in user namespaces where untrusted workloads run, using seccomp or namespace policy
- Reboot into the patched kernel; live-patching may not cover the fix depending on the distribution
Patch Information
The upstream fix reads dst->dev through dst_dev_rcu() and keeps the RCU read-side critical section active until xfrm_fill_dst() has taken the required device references. Review the patches at kernel.org commit 8d85d6bc and kernel.org commit 9fa903b2. Consult distribution security advisories for backported stable kernel releases.
Workarounds
- Disable IPv6 xfrm policy processing on hosts that do not require IPsec over IPv6
- Prevent unprivileged user namespace creation by setting kernel.unprivileged_userns_clone=0 where supported
- Constrain containers from issuing netlink link administration via Linux Security Modules or runtime security policies
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.