{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-31406","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-03-09T15:48:24.086Z","datePublished":"2026-04-06T07:38:18.840Z","dateUpdated":"2026-05-11T22:08:05.678Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T22:08:05.678Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini()\n\nAfter cancel_delayed_work_sync() is called from\nxfrm_nat_keepalive_net_fini(), xfrm_state_fini() flushes remaining\nstates via __xfrm_state_delete(), which calls\nxfrm_nat_keepalive_state_updated() to re-schedule nat_keepalive_work.\n\nThe following is a simple race scenario:\n\n           cpu0                             cpu1\n\ncleanup_net() [Round 1]\n  ops_undo_list()\n    xfrm_net_exit()\n      xfrm_nat_keepalive_net_fini()\n        cancel_delayed_work_sync(nat_keepalive_work);\n      xfrm_state_fini()\n        xfrm_state_flush()\n          xfrm_state_delete(x)\n            __xfrm_state_delete(x)\n              xfrm_nat_keepalive_state_updated(x)\n                schedule_delayed_work(nat_keepalive_work);\n  rcu_barrier();\n  net_complete_free();\n  net_passive_dec(net);\n    llist_add(&net->defer_free_list, &defer_free_list);\n\ncleanup_net() [Round 2]\n  rcu_barrier();\n  net_complete_free()\n    kmem_cache_free(net_cachep, net);\n                                     nat_keepalive_work()\n                                       // on freed net\n\nTo prevent this, cancel_delayed_work_sync() is replaced with\ndisable_delayed_work_sync()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"}}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"versions":[{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"32d0f44c2f14d60fe8e920e69a28c11051543ec1","status":"affected","versionType":"git"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"2255ed6adbc3100d2c4a83abd9d0396d04b87792","status":"affected","versionType":"git"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"21f2fc49ca6faa393c31da33b8a4e6c41fc84c13","status":"affected","versionType":"git"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"daf8e3b253aa760ff9e96c7768a464bc1d6b3c90","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","status":"unaffected","versionType":"semver"},{"version":"6.12.80","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.21","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"6.19.11","lessThanOrEqual":"6.19.*","status":"unaffected","versionType":"semver"},{"version":"7.0","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.12.80"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.18.21"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"6.19.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.11","versionEndExcluding":"7.0"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/32d0f44c2f14d60fe8e920e69a28c11051543ec1"},{"url":"https://git.kernel.org/stable/c/2255ed6adbc3100d2c4a83abd9d0396d04b87792"},{"url":"https://git.kernel.org/stable/c/21f2fc49ca6faa393c31da33b8a4e6c41fc84c13"},{"url":"https://git.kernel.org/stable/c/daf8e3b253aa760ff9e96c7768a464bc1d6b3c90"}],"title":"xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini()","x_generator":{"engine":"bippy-1.2.0"}}}}