Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cache
Impact
If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cache jumps to the found label while the acquire path is entered with an uninitialized state_ptrs structure. The SA selection path then works off stack garbage - a wild-pointer read/write in the code that decides which security association a flow gets, which is both a corruption primitive and a wrong-SA risk.
Who can reach it
Driven by any outbound flow that needs an SA on an IPsec-enabled node - tenant traffic on an encrypted overlay is enough; the race needs preemption between the cache lookup and the acquire branch, which ordinary scheduling on a busy node provides. Requires the per-CPU xfrm state cache (6.7 and later kernels) and configured xfrm policy.
What to do
Update to 6.12.41 or later in the 6.12 series, or a kernel carrying the linked stable commits. Interim: no meaningful workaround short of disabling IPsec on the node.
References
Related entries
- Linux kernel (net/xfrm): SPI 0 means 'no SPI assigned', but the duplicate-SPI rework started creating states with SPI 0CVE-2025-39965 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback canCVE-2026-23239 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Flushing xfrm states during namespace cleanup re-arms the NAT-keepalive delayed work after itCVE-2026-31406 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): An XFRM_MSG_NEWSPDINFO request queues a per-namespace work item on the global systemCVE-2026-31516 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): SA deletion decided whether to unhash from the by-SPI and by-sequence chains using fieldCVE-2026-46116 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): ESP-in-TCP keeps a single in-flight transmit. For a blocking caller the flush of that stateCVE-2026-52935 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.