{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98229","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.328Z","datePublished":"2026-10-06T08:45:03.904Z","dateUpdated":"2026-10-07T06:49:32.876Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-07T06:49:32.876Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: save input state data before secpath resets\n\nxfrm_input() stores the current xfrm_state in the skb secpath while it\ncontinues receive-side processing. Some input paths can reset that secpath\nbefore xfrm_input() has finished dereferencing the state.\n\nReceive callback users such as VTI and XFRM interfaces can reset the\nsecpath. The VTI receive path does so before checking whether the packet\ncrosses network namespaces, while the XFRM interface path does so only for\ncross-network-namespace packets. The XFRM_MAX_DEPTH error path can also\nreset the secpath before the final drop callback reports the current\nstate's protocol.\n\nIf secpath_reset() drops the last state reference while the state is\nconcurrently deleted, xfrm_input() can still dereference the freed state\nwhen selecting transport_finish() or reporting the drop callback protocol.\n\nSave the state protocol on the stack while the state is still valid,\nand use the already saved address family for transport_finish(). A larval\nXFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This\npreserves the existing drop-path fallback while avoiding the post-reset\nstate dereferences without adding an extra state reference to every\nreceived packet."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Freeing the state requires deleting the SA while xfrm_input() is still using it; the packet bytes themselves are not malformed. The attacker who can both inject ESP into a VTI/xfrmi device and send XFRM_MSG_DELSA is a local user acting through netlink in their own netns. A remote IPsec peer cannot delete the SA at will.\nAC:L - placeholder\nPR:L - placeholder\nUI:N - placeholder\nS:U - placeholder\nC:H - placeholder\nI:H - placeholder\nA:H - placeholder"}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/xfrm/xfrm_input.c"],"versions":[{"version":"df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0","lessThan":"35de97850987b3d022ed17df5b2577242e746daf","status":"affected","versionType":"git"},{"version":"df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0","lessThan":"148db154066b066616b82c12d373e786eba1f96a","status":"affected","versionType":"git"},{"version":"df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0","lessThan":"537a5ae18b2be70f8eb0aca843682e81a69aab91","status":"affected","versionType":"git"},{"version":"df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0","lessThan":"3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/xfrm/xfrm_input.c"],"versions":[{"version":"3.15","status":"affected"},{"version":"0","lessThan":"3.15","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.15","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/35de97850987b3d022ed17df5b2577242e746daf"},{"url":"https://git.kernel.org/stable/c/148db154066b066616b82c12d373e786eba1f96a"},{"url":"https://git.kernel.org/stable/c/537a5ae18b2be70f8eb0aca843682e81a69aab91"},{"url":"https://git.kernel.org/stable/c/3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa"}],"title":"xfrm: save input state data before secpath resets","x_generator":{"engine":"bippy-1.2.0"}}}}