Skip to main content
Vulnerability Database/CVE-2026-98368

CVE-2026-98368: Linux Kernel Use-After-Free Vulnerability

CVE-2026-98368 is a use-after-free flaw in the Linux kernel ESP implementation affecting zerocopy managed fragments. This critical issue can lead to memory corruption and system instability. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-98368 Overview

CVE-2026-98368 is a Linux kernel vulnerability in the Encapsulating Security Payload (ESP) output path. The flaw affects the out-of-place output path when esp->inplace == false and the socket buffer (skb) carries zerocopy managed frags marked with SKBFL_MANAGED_FRAG_REFS. ESP rewrites the skb frag array in esp_output_head() and esp_output_tail() without downgrading the managed-frag ownership first. This produces two defects: a use-after-free of pinned zerocopy pages and a reference leak of the destination page. The issue has been resolved upstream through multiple stable branch backports.

Critical Impact

A local user leveraging zerocopy IPsec traffic can trigger a use-after-free on pinned user pages and a per-packet memory leak, enabling local privilege escalation or denial of service.

Affected Products

  • Linux kernel ESP (IPsec) output path with zerocopy support
  • Stable kernel branches referenced in the backport commits
  • Systems using IPsec transforms with MSG_ZEROCOPY or similar managed-frag senders

Discovery Timeline

  • 2026-10-06 - CVE-2026-98368 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-98368

Vulnerability Analysis

The ESP output path mutates the skb fragment array on the out-of-place code path. esp_output_head() appends a trailer frag, and esp_output_tail() replaces the frags with a destination page, taking references via get_page(). When the skb carries payload frags owned by a zerocopy ubuf, those frags must not be referenced or unreferenced individually — the ubuf owns the lifetime through the GUP pin.

Two invariant violations result. First, esp_ssg_unref() walks the source scatterlist and drops a page reference for every frag, including ubuf-owned payload frags. This pushes their refcount below the GUP pin bias while the pages remain pinned, producing a use-after-free against the zerocopy pages. Second, esp_output_tail() installs its destination page as frag 0 with get_page() but leaves SKBFL_MANAGED_FRAG_REFS set. skb_release_data() then takes the skip_unref branch and never drops that reference, leaking the x->xfrag page at packet rate.

Root Cause

The root cause is a missing downgrade of the managed-frag ownership before ESP mutates the frag array. Other frag-mutating call sites — __ip_append_data(), __ip6_append_data(), and tcp_sendmsg_locked() — invoke skb_zcopy_downgrade_managed() first to take a real reference on each existing frag and clear SKBFL_MANAGED_FRAG_REFS. ESP omitted this step, leaving a mixed-ownership frag array.

Attack Vector

Exploitation requires local access and the ability to send IPsec-protected traffic using zerocopy sends such as MSG_ZEROCOPY through an SA that selects the out-of-place ESP output path. A local user with network transmit privileges can trigger both the use-after-free of pinned user pages and the per-packet reference leak, impacting confidentiality, integrity, and availability.

No public proof-of-concept exploit is available. See the upstream fix in Kernel Commit 0d0845ee for the canonical patch.

Detection Methods for CVE-2026-98368

Indicators of Compromise

  • Kernel oops or KASAN use-after-free reports originating from esp_ssg_unref, esp_output_tail, or skb_release_data on IPsec egress paths.
  • Steady growth in kernel page accounting correlated with sustained IPsec traffic from processes using MSG_ZEROCOPY.
  • Unexpected process termination or memory corruption on hosts running IPsec with zerocopy-enabled userspace senders.

Detection Strategies

  • Enable KASAN on test kernels and replay IPsec zerocopy workloads to surface the use-after-free deterministically.
  • Audit running kernel versions against the fixed commits listed in the vendor advisories to identify unpatched hosts.
  • Monitor /proc/meminfo and slab counters on IPsec gateways for anomalous page leak patterns at packet rate.

Monitoring Recommendations

  • Collect kernel ring buffer logs centrally and alert on stack traces containing esp_output_tail or esp_ssg_unref.
  • Track IPsec throughput against kernel memory consumption on gateways to detect the leak signature.
  • Inventory which workloads use MSG_ZEROCOPY over IPsec SAs and prioritize those hosts for patching.

How to Mitigate CVE-2026-98368

Immediate Actions Required

  • Apply the stable kernel update that calls skb_zcopy_downgrade_managed() before ESP mutates the frag array.
  • Restrict local accounts on IPsec gateways and reduce the attack surface for zerocopy socket senders until patches are deployed.
  • Reboot affected hosts after installing the updated kernel package to activate the fix.

Patch Information

The upstream fix adds a skb_zcopy_downgrade_managed() call before ESP touches the frag array, taking a real reference on each existing frag and clearing SKBFL_MANAGED_FRAG_REFS. This balances the per-frag unref in esp_ssg_unref() and the frag release in skb_release_data(). Backports are available in Kernel Commit 0d0845ee, Kernel Commit 2359264f, Kernel Commit 6508304a, Kernel Commit 69a768c1, Kernel Commit 6cab554f, and Kernel Commit f89416eb.

Workarounds

  • Disable MSG_ZEROCOPY or equivalent managed-frag sends on applications routed through IPsec SAs using the out-of-place ESP output path.
  • Where feasible, prefer the in-place ESP output path by adjusting cryptographic transform selection to avoid triggering the vulnerable code.
  • Limit shell access on IPsec endpoints to trusted administrators until the kernel update is applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.