Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): A qdisc that reuses skb
Impact
A qdisc that reuses skb->cb during enqueue clobbers the state decode_session6 relies on, so transmitting IPv6 through an xfrm interface reads freed slab memory while deciding which policy and SA the packet belongs to. Memory-safety break in the path that classifies traffic for encryption.
Who can reach it
Requires an xfrm interface with a cb-clobbering qdisc such as sfb attached, then any IPv6 transmit through it - neighbour discovery traffic is enough. A container with CAP_NET_ADMIN in its own netns can attach the qdisc itself and then send; otherwise it depends on the node's qdisc configuration on the encrypted overlay device.
What to do
Boot a kernel carrying the linked stable commits. Interim: do not attach sfb (or other cb-using qdiscs) to xfrm interfaces, and drop CAP_NET_ADMIN from tenant containers so they cannot attach one.
References
Related entries
- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forCVE-2026-68420 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenCVE-2024-50142 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksCVE-2026-53197 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The policy-hash rebuild preallocates for exactly the wrong half of the policy set - the guardCVE-2026-64579 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.