Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): Cloning an IPTFS security association kmemdups the mode data, so the clone shares the original
Impact
Cloning an IPTFS security association kmemdups the mode data, so the clone shares the original SA's skb queue, hrtimers, spinlock and in-flight reassembly state. If migration fails before re-init, destroying the clone splices and frees skbs still owned by the original SA - use-after-free and double-free of packet buffers belonging to a live encrypted association.
Who can reach it
Driven by XFRM_MSG_MIGRATE (or SA clone during migration) over xfrm netlink, requiring CAP_NET_ADMIN in the network namespace - available to the node's IKE daemon and to any container granted NET_ADMIN with its own netns. Conditional on IPTFS-mode SAs (RFC 9347 aggregation) being in use, and the corruption is most reachable when the SA has packets queued, which an attacker arranges by migrating under load.
What to do
Boot a kernel carrying the linked stable commits. Interim: avoid IPTFS mode SAs, do not run SA migration on nodes using IPTFS, and drop CAP_NET_ADMIN from tenant containers.
References
Related entries
- Linux kernel (net/xfrm): An unprivileged user who can create IPsec SAs turns one outbound datagram into a multi-exabyteCVE-2026-64009 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Setting a per-socket IPsec policy reset the socket's destination cache non-atomically whileCVE-2026-64581 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Xfrm_selector_match() compared selectors without checking that the selector family matches theCVE-2026-72450 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soCVE-2025-38057 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Xfrm_alloc_spi could hand out an SPI that is already in use by another inbound SA, because theCVE-2025-39797 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): One crafted inner IPv4 header (tot_len = 0) inside an IPTFS payload puts the receive path intoCVE-2026-31472 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.