Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback can
Impact
Closing an ESP-in-TCP socket cancels its transmit work item, but the write-space callback can re-schedule that work from softirq immediately afterwards. The worker then runs against a freed espintcp context or a freed socket - a use-after-free on teardown whose timing is supplied by the peer's acknowledgement behaviour. Same defect shape as the kTLS one in CVE-2026-23240, in the IPsec-over-TCP path.
Who can reach it
A local process that attaches the espintcp ULP to a TCP socket (no privilege beyond owning the socket) and closes it with data still in flight. The re-schedule comes from the delayed-ACK handler or ksoftirqd, so a remote peer on the fabric can widen the window by controlling when it acknowledges. Conditional on CONFIG_INET_ESPINTCP. Found by source audit.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published). Interim control: disable CONFIG_INET_ESPINTCP on nodes that do not need IPsec-over-TCP so the ULP cannot be attached.
References
Related entries
- Linux kernel (net/xfrm): Flushing xfrm states during namespace cleanup re-arms the NAT-keepalive delayed work after itCVE-2026-31406 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): An XFRM_MSG_NEWSPDINFO request queues a per-namespace work item on the global systemCVE-2026-31516 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): SA deletion decided whether to unhash from the by-SPI and by-sequence chains using fieldCVE-2026-46116 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): ESP-in-TCP keeps a single in-flight transmit. For a blocking caller the flush of that stateCVE-2026-52935 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Policy deletion dropped the policy lock before pruning the inexact-policy bin, and aCVE-2026-53239 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Cloning an IPTFS security association kmemdups the mode data, so the clone shares the originalCVE-2026-63911 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.