Database/Kernel, userspace & hypervisor
Linux kernel (net/xfrm): NAT-keepalive frees the keepalive skb whenever the IPv4/IPv6 send helper returns an error
Impact
NAT-keepalive frees the keepalive skb whenever the IPv4/IPv6 send helper returns an error, including after the output path has already taken ownership and consumed it. Any send failure on a keepalive turns into a double free - kernel heap corruption on a node doing NAT-traversal IPsec.
Who can reach it
Remote-influenced rather than remote-executed: the keepalive timer runs on its own, and whether the send fails after handoff depends on network conditions an off-path party can shape (route loss, neighbour failure, MTU/ICMP responses). Conditional on NAT-T keepalives being configured on SAs, which is standard when IPsec crosses NAT or cloud gateways. No local privilege or device node needed.
What to do
Boot a kernel carrying the linked stable commits. Interim: disable NAT keepalives on SAs that do not need them (no NAT in the path), which removes the code path entirely.
References
Related entries
- Linux kernel (net/xfrm): The IPsec input path validates a security association before taking the state lock, so a stateCVE-2026-72451 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): Async ESP resumption holds a reference on the original skbCVE-2026-72463 · Linux kernel (net/xfrm)Critical
- Linux kernel (net/xfrm): An unlocked read of the IPTFS reassembly state lets two CPUs disagree about who owns a socketCVE-2026-53240 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): Transport-mode reinjection stashes a network-namespace pointer in the socket buffer's controlCVE-2026-63919 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): The rtnetlink changelink path for xfrm interfaces checked CAP_NET_ADMIN only against theCVE-2026-72136 · Linux kernel (net/xfrm)High
- Linux kernel (net/xfrm): The error path of xfrm_input leaves the secpath entry pointing at poisoned memory, and theCVE-2024-43878 · Linux kernel (net/xfrm)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.