Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Structure padding in the xfrm algorithm and encapsulation templates was copied to userspace
Impact
Structure padding in the xfrm algorithm and encapsulation templates was copied to userspace without being zeroed, so every SA dump hands out whatever was in those slab bytes. Small but reliable kernel-memory disclosure from inside a namespace.
Who can reach it
XFRM_MSG_GETSA / policy dumps over xfrm netlink, requiring CAP_NET_ADMIN in the network namespace - which a container granted NET_ADMIN with its own netns has. No fabric access needed; this is a container-to-host information leak.
What to do
Boot a kernel carrying the linked stable commits. Interim: drop CAP_NET_ADMIN from tenant containers.
References
Related entries
- Linux kernel (net/xfrm): Dumping SAs over xfrm netlink copies algorithm structures that were never fully initializedCVE-2024-50110 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeCVE-2023-52746 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCVE-2026-53363 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The same ownership-marker bug as CVE-2026-53363, in the other IPTFS frag-transfer helper.CVE-2026-64566 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): When IPsec crypto offload takes a GSO segment asynchronously, the segment is unlinked from theCVE-2026-68426 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The ESP-in-TCP send path mis-tracked scatter-gather message offsets and socket memory chargesCVE-2026-72041 · Linux kernel (net/xfrm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.