{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-38097","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T04:51:23.985Z","datePublished":"2025-07-03T08:13:57.694Z","dateUpdated":"2026-08-05T11:59:29.885Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:59:29.885Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: remove encap socket caching to avoid reference leak\n\nThe current scheme for caching the encap socket can lead to reference\nleaks when we try to delete the netns.\n\nThe reference chain is: xfrm_state -> enacp_sk -> netns\n\nSince the encap socket is a userspace socket, it holds a reference on\nthe netns. If we delete the espintcp state (through flush or\nindividual delete) before removing the netns, the reference on the\nsocket is dropped and the netns is correctly deleted. Otherwise, the\nnetns may not be reachable anymore (if all processes within the ns\nhave terminated), so we cannot delete the xfrm state to drop its\nreference on the socket.\n\nThis patch results in a small (~2% in my tests) performance\nregression.\n\nA GC-type mechanism could be added for the socket cache, to clear\nreferences if the state hasn't been used \"recently\", but it's a lot\nmore complex than just not caching the socket."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The entire attack is driven through local syscalls — `socket()`+`setsockopt(TCP_ULP,\"espintcp\")` to create the encap socket, NETLINK_XFRM to add/flush the SA and policy, and local traffic to trigger `esp_output_tail_tcp()`. No remote peer input is needed to populate or tear down the cached socket reference.\nAC:L - The reference leak itself is fully deterministic — create the SA, send one packet, let the namespace go away — with no race or memory-layout dependency, and `CONFIG_INET_ESPINTCP`/`CONFIG_INET6_ESPINTCP` are enabled in mainstream distro kernels. For the dangling-`encap_sk` window the attacker drives both sides (a traffic generator feeding `xfrm_trans_queue_net()` and a concurrent `xfrm state flush` loop) and can retry indefinitely.\nPR:L - Adding the xfrm state requires CAP_NET_ADMIN, but `xfrm_user.c` uses `netlink_net_capable()`, which resolves against `sock_net(skb->sk)->user_ns`, so an ordinary unprivileged user obtains it with `unshare -Urn`; attaching the espintcp ULP requires no privilege at all. No real root in the init namespace is needed.\nUI:N - The attacker performs every step — socket setup, SA installation, packet transmission, and namespace teardown — entirely on their own. No victim action or cooperating process is involved.\nS:U - The leaked netns/socket and the dangling socket dereference are all kernel objects under the same security authority as the attacking context; no VM, IOMMU, or hypervisor boundary is crossed.\nC:H - After `__xfrm_state_delete()` drops the socket reference without RCU synchronization and leaves `x->encap_sk` non-NULL, the deferred `esp_find_tcp_sk()` reads `sk->sk_state` and then operates on that released socket; because TCP sockets come from a SLAB_TYPESAFE_BY_RCU cache the slot can already hold an attacker-groomed socket, and `espintcp_getctx()` then follows a foreign `icsk_ulp_data`, giving a use-after-free read primitive over attacker-influenced kernel memory.\nI:H - The stale `x->encap_sk` also lets the slow path match `sk == nsk` and queue a second `sock_put()` through `call_rcu(esp_free_tcp_sk)`, a refcount underflow that frees a socket userspace still references by fd — a classic UAF write/heap-grooming primitive, and `bh_lock_sock()`/`espintcp_push_skb()` write into the freed object directly.\nA:H - Each leaked SA permanently pins an entire `struct net` (with all per-net subsystem allocations, sysctls, procfs entries and per-cpu data) that can never be reclaimed, and an unprivileged user can repeat this in a loop until kernel memory is exhausted or netns ucount limits break container creation; the dangling-socket dereference additionally oopses the kernel."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/xfrm.h","net/ipv4/esp4.c","net/ipv6/esp6.c","net/xfrm/xfrm_state.c"],"versions":[{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"e4cde54b46a87231c77256a633be1bef62687d69","status":"affected","versionType":"git"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"b58a295d10065960bcb9d60cb8ca6ead9837cd27","status":"affected","versionType":"git"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"9cbca30102028f9ad3d2098f935c4368f581fd07","status":"affected","versionType":"git"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"74fd327767fb784c5875cf7c4ba1217f26020943","status":"affected","versionType":"git"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"028363685bd0b7a19b4a820f82dd905b1dc83999","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/xfrm.h","net/ipv4/esp4.c","net/ipv6/esp6.c","net/xfrm/xfrm_state.c"],"versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","status":"unaffected","versionType":"semver"},{"version":"6.1.141","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.93","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.31","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.14.9","lessThanOrEqual":"6.14.*","status":"unaffected","versionType":"semver"},{"version":"6.15","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.1.141"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.6.93"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.12.31"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.14.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6","versionEndExcluding":"6.15"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e4cde54b46a87231c77256a633be1bef62687d69"},{"url":"https://git.kernel.org/stable/c/b58a295d10065960bcb9d60cb8ca6ead9837cd27"},{"url":"https://git.kernel.org/stable/c/9cbca30102028f9ad3d2098f935c4368f581fd07"},{"url":"https://git.kernel.org/stable/c/74fd327767fb784c5875cf7c4ba1217f26020943"},{"url":"https://git.kernel.org/stable/c/028363685bd0b7a19b4a820f82dd905b1dc83999"}],"title":"espintcp: remove encap socket caching to avoid reference leak","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T17:34:02.117Z"}}]}}