Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makes
Impact
A peer that mixes zero-copy-eligible and copy-path IPTFS fragments in one datagram makes reassembly call skb_put() on an already non-linear buffer, hitting SKB_LINEAR_ASSERT and taking an invalid-opcode fault in NAPI softirq. That is a hard kernel panic driven by packet shape - every tenant on the node loses its GPUs, and the sender can repeat it after each reboot.
Who can reach it
Inbound ESP on an IPTFS SA; the fragment sequence is chosen by the sender, so any peer holding the SA reaches it - a peer node, a compromised node, or the far side of a tenant overlay tunnel. The published call trace runs straight from the NIC driver's NAPI poll through xfrm4_esp_rcv into iptfs_reassem_cont, so no local access or tenant device node is involved. Conditional on IPTFS mode being configured.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published). Interim control: disable IP-TFS mode on SAs that terminate traffic from tenants or from nodes you do not fully trust.
References
Related entries
- Linux kernel (net/xfrm): A qdisc that reuses skbCVE-2023-53500 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Outbound policies rejected optional tunnel and BEET templates but never got the same check forCVE-2026-68420 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): An SA created with an AF_UNSPEC selector escaped prefix-length validation, and the kernel thenCVE-2024-50142 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksCVE-2026-53197 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.