Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locks
Impact
Tearing down an IPTFS security association cancels its hrtimers while holding the very locks those timer callbacks take. On SMP that closes an ABBA cycle - one CPU spins on the softirq expiry lock while the softirq holding it waits for the spinlock the canceller owns. Neither side ever progresses, so a lock held on the IPsec datapath is never released and packet processing on the node stops. Every tenant on that host loses fabric connectivity until it is power-cycled.
Who can reach it
Requires the ability to delete an IPTFS xfrm state while its output or drop timer is firing - host root, or a tenant container holding CAP_NET_ADMIN in its own user+network namespace, which can create and delete IPTFS SAs in a loop while pushing traffic through them to keep the timers hot. Conditional on IP-TFS mode being available. Found by source-code audit rather than a fuzzer, so treat the deadlock as reachable but not yet weaponised in public.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published). Interim control: remove CAP_NET_ADMIN from tenant user namespaces so tenants cannot churn IPTFS SAs, or blacklist xfrm_iptfs where IP-TFS is not deliberately in use.
References
Related entries
- Linux kernel (net/xfrm): The policy-hash rebuild preallocates for exactly the wrong half of the policy set - the guardCVE-2026-64579 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Transmitting a packet carrying a metadata dst (no dstCVE-2022-50004 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Transport-mode IPsec packets were reinjected in the same execution context instead of beingCVE-2022-50445 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Structure padding in the xfrm algorithm and encapsulation templates was copied to userspaceCVE-2023-53684 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): Dumping SAs over xfrm netlink copies algorithm structures that were never fully initializedCVE-2024-50110 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeCVE-2023-52746 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.