Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): SA lookup can observe the new hash mask before the new bucket array is published, so it
Impact
SA lookup can observe the new hash mask before the new bucket array is published, so it indexes past the end of the old table - an out-of-bounds read in the code path that decides which security association handles a packet. Besides the read, a lookup that lands in garbage can miss or mismatch the SA for in-flight traffic.
Who can reach it
Driven by packet processing on any IPsec-enabled node while the state table is resized. The resize happens as SAs are added, i.e. as tenants' IPsec tunnels come and go, so the race window opens during normal churn on a per-tenant encrypted overlay. Anyone who can cause SA creation (the IKE daemon, or a container with CAP_NET_ADMIN in its netns) can force the rehash on demand.
What to do
Boot a kernel carrying the linked stable commits. Interim: pre-size the xfrm state hash where possible and avoid rapid SA churn; drop CAP_NET_ADMIN from tenant containers so they cannot force rehashing.
References
Related entries
- Linux kernel (net/xfrm): The guard that forbids changing a collect_md xfrm interface never fired, so a changelink putsCVE-2025-38500 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cacheCVE-2025-38675 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): SPI 0 means 'no SPI assigned', but the duplicate-SPI rework started creating states with SPI 0CVE-2025-39965 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback canCVE-2026-23239 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Flushing xfrm states during namespace cleanup re-arms the NAT-keepalive delayed work after itCVE-2026-31406 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): An XFRM_MSG_NEWSPDINFO request queues a per-namespace work item on the global systemCVE-2026-31516 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.