Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98370— xfrm: fix compat ALLOCSPI request use-after-free

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: xfrm:修复兼容模式(compat)ALLOCSPI 请求中的释放后使用(use-after-free)漏洞 使用 构建 ALLOCSPI 响应,而 已经使用响应 skb 和头部调用了 。 随后, 再次调用 ,但传递的是原始请求的 skb 及其头部。对于兼容模式请求,翻译器因此会将 228 字节的兼容模式 错误地解释为 232 字节的本机布局,从而读取了超出声明载荷的四个字节。此外,它还将转换后的子节点通过请求的 发布出去。 请求的多播克隆副本共享 ,能够观察到该子节点。

AI Predicted 7.8 Difficulty: Hard EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< 17893987e52918c23945c42e47e894a936305a25 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< bb63ab52a18273ec68340ac49aebbaa7b514ccd5 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< 248433942155b42a0ef04a5806c8aca024ea7c33 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< e70f639aee2ff0def155c256cace9e0f81d998e2 affected
5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3< d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98370

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xfrm: fix compat ALLOCSPI request use-after-free
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 ~ 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 -
Linux Linux 5.10 -

II. Public POCs for CVE-2026-98370

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98370

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98370 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98281 7.8 HIGH futex: Also allocate private hash on vfork()
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98253 7.8 HIGH RDMA/ucma: Serialize join and leave on copy_to_user failure
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98370

No comments yet


Leave a comment