Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, so
Impact
Several error paths in the ESP-in-TCP receive code return without freeing the skb, so malformed or failing frames leak socket buffers. A peer that keeps feeding the error path drains kernel memory on the node until the OOM killer starts taking tenant workloads with it.
Who can reach it
Remote, driven by whatever can reach the espintcp encapsulation socket (TCP port 4500 by default) on a node using ESP-in-TCP encapsulation for IPsec through NAT/middleboxes. Conditional: only nodes with espintcp configured are affected; plain UDP-encapsulated or raw ESP setups are not.
What to do
Boot a kernel carrying the linked stable commits. Interim: drop ESP-in-TCP encapsulation if it is not required, or firewall the espintcp port to known IKE peers only.
References
Related entries
- Linux kernel (net/xfrm): Xfrm_alloc_spi could hand out an SPI that is already in use by another inbound SA, because theCVE-2025-39797 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path intoCVE-2026-31472 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makesCVE-2026-31517 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): A qdisc that reuses skbCVE-2023-53500 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forCVE-2026-68420 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.