CVE-2026-98368 Overview
CVE-2026-98368 is a Linux kernel vulnerability in the Encapsulating Security Payload (ESP) output path. The flaw affects the out-of-place output path when esp->inplace == false and the socket buffer (skb) carries zerocopy managed frags marked with SKBFL_MANAGED_FRAG_REFS. ESP rewrites the skb frag array in esp_output_head() and esp_output_tail() without downgrading the managed-frag ownership first. This produces two defects: a use-after-free of pinned zerocopy pages and a reference leak of the destination page. The issue has been resolved upstream through multiple stable branch backports.
Critical Impact
A local user leveraging zerocopy IPsec traffic can trigger a use-after-free on pinned user pages and a per-packet memory leak, enabling local privilege escalation or denial of service.
Affected Products
- Linux kernel ESP (IPsec) output path with zerocopy support
- Stable kernel branches referenced in the backport commits
- Systems using IPsec transforms with MSG_ZEROCOPY or similar managed-frag senders
Discovery Timeline
- 2026-10-06 - CVE-2026-98368 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-98368
Vulnerability Analysis
The ESP output path mutates the skb fragment array on the out-of-place code path. esp_output_head() appends a trailer frag, and esp_output_tail() replaces the frags with a destination page, taking references via get_page(). When the skb carries payload frags owned by a zerocopy ubuf, those frags must not be referenced or unreferenced individually — the ubuf owns the lifetime through the GUP pin.
Two invariant violations result. First, esp_ssg_unref() walks the source scatterlist and drops a page reference for every frag, including ubuf-owned payload frags. This pushes their refcount below the GUP pin bias while the pages remain pinned, producing a use-after-free against the zerocopy pages. Second, esp_output_tail() installs its destination page as frag 0 with get_page() but leaves SKBFL_MANAGED_FRAG_REFS set. skb_release_data() then takes the skip_unref branch and never drops that reference, leaking the x->xfrag page at packet rate.
Root Cause
The root cause is a missing downgrade of the managed-frag ownership before ESP mutates the frag array. Other frag-mutating call sites — __ip_append_data(), __ip6_append_data(), and tcp_sendmsg_locked() — invoke skb_zcopy_downgrade_managed() first to take a real reference on each existing frag and clear SKBFL_MANAGED_FRAG_REFS. ESP omitted this step, leaving a mixed-ownership frag array.
Attack Vector
Exploitation requires local access and the ability to send IPsec-protected traffic using zerocopy sends such as MSG_ZEROCOPY through an SA that selects the out-of-place ESP output path. A local user with network transmit privileges can trigger both the use-after-free of pinned user pages and the per-packet reference leak, impacting confidentiality, integrity, and availability.
No public proof-of-concept exploit is available. See the upstream fix in Kernel Commit 0d0845ee for the canonical patch.
Detection Methods for CVE-2026-98368
Indicators of Compromise
- Kernel oops or KASAN use-after-free reports originating from esp_ssg_unref, esp_output_tail, or skb_release_data on IPsec egress paths.
- Steady growth in kernel page accounting correlated with sustained IPsec traffic from processes using MSG_ZEROCOPY.
- Unexpected process termination or memory corruption on hosts running IPsec with zerocopy-enabled userspace senders.
Detection Strategies
- Enable KASAN on test kernels and replay IPsec zerocopy workloads to surface the use-after-free deterministically.
- Audit running kernel versions against the fixed commits listed in the vendor advisories to identify unpatched hosts.
- Monitor /proc/meminfo and slab counters on IPsec gateways for anomalous page leak patterns at packet rate.
Monitoring Recommendations
- Collect kernel ring buffer logs centrally and alert on stack traces containing esp_output_tail or esp_ssg_unref.
- Track IPsec throughput against kernel memory consumption on gateways to detect the leak signature.
- Inventory which workloads use MSG_ZEROCOPY over IPsec SAs and prioritize those hosts for patching.
How to Mitigate CVE-2026-98368
Immediate Actions Required
- Apply the stable kernel update that calls skb_zcopy_downgrade_managed() before ESP mutates the frag array.
- Restrict local accounts on IPsec gateways and reduce the attack surface for zerocopy socket senders until patches are deployed.
- Reboot affected hosts after installing the updated kernel package to activate the fix.
Patch Information
The upstream fix adds a skb_zcopy_downgrade_managed() call before ESP touches the frag array, taking a real reference on each existing frag and clearing SKBFL_MANAGED_FRAG_REFS. This balances the per-frag unref in esp_ssg_unref() and the frag release in skb_release_data(). Backports are available in Kernel Commit 0d0845ee, Kernel Commit 2359264f, Kernel Commit 6508304a, Kernel Commit 69a768c1, Kernel Commit 6cab554f, and Kernel Commit f89416eb.
Workarounds
- Disable MSG_ZEROCOPY or equivalent managed-frag sends on applications routed through IPsec SAs using the out-of-place ESP output path.
- Where feasible, prefer the in-place ESP output path by adjusting cryptographic transform selection to avoid triggering the vulnerable code.
- Limit shell access on IPsec endpoints to trusted administrators until the kernel update is applied.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.