Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Dumping SAs over xfrm netlink copies algorithm structures that were never fully initialized
Impact
Dumping SAs over xfrm netlink copies algorithm structures that were never fully initialized, so ~50 bytes of uninitialized kernel heap per algorithm are handed to userspace. That is a kernel-memory read primitive useful for defeating KASLR or recovering adjacent slab contents from inside a container.
Who can reach it
XFRM_MSG_GETSA dump over netlink, which needs CAP_NET_ADMIN in the network namespace - satisfied by any container granted NET_ADMIN with its own netns, and by the node's IKE daemon. The caller adds an SA (attach_auth allocates the buffer) and then dumps it back to read the uninitialized tail.
What to do
Boot a kernel carrying the linked stable commits. Interim: drop CAP_NET_ADMIN from tenant containers so the xfrm netlink dump surface is not exposed to them.
References
Related entries
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeCVE-2023-52746 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCVE-2026-53363 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The same ownership-marker bug as CVE-2026-53363, in the other IPTFS frag-transfer helper.CVE-2026-64566 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): When IPsec crypto offload takes a GSO segment asynchronously, the segment is unlinked from theCVE-2026-68426 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): The ESP-in-TCP send path mis-tracked scatter-gather message offsets and socket memory chargesCVE-2026-72041 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): NAT-keepalive frees the keepalive skb whenever the IPv4/IPv6 send helper returns an errorCVE-2026-72137 · Linux kernel (net/xfrm)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.