Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path into
Impact
One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path into an infinite loop in softirq context. The CPU never leaves the loop, so a single packet takes a core out permanently and wedges packet processing on the node - a fabric-wide stall and an outage for every tenant sharing that host, from one packet, repeatable at will.
Who can reach it
The malformed header is inside the decrypted IPTFS payload, so the sender must be a valid peer on the SA - a peer node on the cluster fabric, a compromised node, or a tenant endpoint terminating an overlay tunnel whose key the tenant holds. Conditional on IPTFS mode being configured. No local access to the victim node is required; the inner header never reaches ip_rcv_core, which is where this validation normally happens.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published in the record). Interim control: stop terminating tenant-controlled or untrusted IPTFS tunnels on shared nodes, and drop IP-TFS mode in favour of plain ESP tunnel mode until patched.
References
Related entries
- Linux kernel (net/xfrm): A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makesCVE-2026-31517 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): A qdisc that reuses skbCVE-2023-53500 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forCVE-2026-68420 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenCVE-2024-50142 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.