CVE-2026-98241 (GCVE-0-2026-98241)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-07 06:49
VLAI
Title
ipv6: xfrm: use full sockets in local error paths
Summary
In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it always pointed at a full IPv6 socket. That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb. The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request_sock allocation when they access inet_sock or ipv6_pinfo state. Resolve the owner with skb_to_full_sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb_to_full_sk().
Impacted products
Vendor Product Version
Linux Linux Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < b1a88633c36d2cbc3831382f3846754d344276fd (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < 904a0e827d0d7189271a3a2eb648293809f25efc (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < 675919e08ce266b8cac11fd9af29170e762a480f (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < 60459c670329d586a58db5d8f811fa5accfe4862 (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < ca3d68c3213475b53db6647e159dc73bd1af5ab1 (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < 4c030a0400ebfd2318361c923a88103b2c67c49f (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8 (git)
Affected: dd767856a36e00b631d65ebc4bb81b19915532d6 , < 6973a21ee73c5567f883813c8ef414774b45892f (git)
Create a notification for this product.
Linux Linux Affected: 3.2
Unaffected: 0 , < 3.2 (semver)
Unaffected: 5.10.271 , ≤ 5.10.* (semver)
Unaffected: 5.15.222 , ≤ 5.15.* (semver)
Unaffected: 6.1.189 , ≤ 6.1.* (semver)
Unaffected: 6.6.158 , ≤ 6.6.* (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/xfrm6_output.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b1a88633c36d2cbc3831382f3846754d344276fd",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "904a0e827d0d7189271a3a2eb648293809f25efc",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "675919e08ce266b8cac11fd9af29170e762a480f",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "60459c670329d586a58db5d8f811fa5accfe4862",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "ca3d68c3213475b53db6647e159dc73bd1af5ab1",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "4c030a0400ebfd2318361c923a88103b2c67c49f",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            },
            {
              "lessThan": "6973a21ee73c5567f883813c8ef414774b45892f",
              "status": "affected",
              "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv6/xfrm6_output.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.2"
            },
            {
              "lessThan": "3.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.271",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.222",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.189",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.158",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "3.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm: use full sockets in local error paths\n\nxfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb-\u003esk as if it\nalways pointed at a full IPv6 socket.\n\nThat is not guaranteed. TCP SYN-ACK skbs can be owned by a\nTCP_NEW_SYN_RECV request_sock while the output path itself is driven by the\nfull listener. If rerouting selects an IPv6 XFRM tunnel route with a lower\nMTU, the local PMTU/error handling path can reach these callbacks with that\nmini-socket still attached to the skb.\n\nThe callbacks then miscast the request socket as a full inet/IPv6 socket and\ncan read beyond the request_sock allocation when they access inet_sock or\nipv6_pinfo state.\n\nResolve the owner with skb_to_full_sk() in both callbacks and bail out when\nno full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error\nlogic, which already reasons about full sockets with skb_to_full_sk()."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The fixed xfrm6_local_error() is reached via __xfrm6_output() -\u003e xfrm_local_error() only if a rerouted SYN-ACK exceeds an xfrm tunnel MTU below ~100 bytes; that needs local xfrm/route/netfilter setup. A remote SYN carries no malformed data and can\u0027t create this state (IPv4 PMTU floor is 552, xfrm6_tunnel_check_size clamps to 1280).\nAC:L - The attacker builds every precondition: an IPv6-in-IPv4 tunnel-mode xfrm SA/policy, a tiny outer MTU, a LOCAL_OUT reroute, and a TCP listener they connect to. Each SYN deterministically sends a SYN-ACK owned by a TCP_NEW_SYN_RECV request_sock down the !ignore_df \u0026\u0026 toobig branch.\nPR:L - The needed XFRM_MSG_NEWSA/NEWPOLICY, nftables rules and link MTU changes only need CAP_NET_ADMIN in the netns, which an unprivileged user gets via unshare -Urn; the listener and connect() are ordinary syscalls.\nUI:N - The attacker sets up the namespace and drives the handshake that emits the SYN-ACK themselves; no other user has to do anything.\nS:U - The out-of-bounds access corrupts kernel heap memory in the same kernel that enforces the attacker\u0027s namespace; no hypervisor or IOMMU boundary is crossed.\nC:H - xfrm6_local_error() passes the request_sock to ipv6_local_error() as a full IPv6 socket; inet6_test_bit(RECVERR6) reads inet_flags past the end of the tcp6_request_sock allocation, into the next slab object, and the rest of the path keeps reading socket fields out of bounds.\nI:H - If the out-of-bounds RECVERR6 bit is set, sock_queue_err_skb() does atomic_add on an OOB sk_rmem_alloc, links an skb into an OOB sk_error_queue list and calls the OOB sk_error_report pointer: heap writes plus control-flow hijack if the attacker grooms the adjacent object.\nA:H - Treating neighbouring slab memory as sk_error_queue and sk_error_report gives list corruption or a wild indirect call, crashing the kernel; the attacker can repeat it with each SYN."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:36.382Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd"
        },
        {
          "url": "https://git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc"
        },
        {
          "url": "https://git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f"
        },
        {
          "url": "https://git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862"
        },
        {
          "url": "https://git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1"
        },
        {
          "url": "https://git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f"
        },
        {
          "url": "https://git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8"
        },
        {
          "url": "https://git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f"
        }
      ],
      "title": "ipv6: xfrm: use full sockets in local error paths",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98241",
    "datePublished": "2026-10-06T08:45:11.954Z",
    "dateReserved": "2026-09-25T10:25:14.329Z",
    "dateUpdated": "2026-10-07T06:49:36.382Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98241",
      "date": "2026-10-08",
      "epss": "0.00138",
      "percentile": "0.02771"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/ipv6/xfrm6_output.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "b1a88633c36d2cbc3831382f3846754d344276fd",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "904a0e827d0d7189271a3a2eb648293809f25efc",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "675919e08ce266b8cac11fd9af29170e762a480f",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "60459c670329d586a58db5d8f811fa5accfe4862",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ca3d68c3213475b53db6647e159dc73bd1af5ab1",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "4c030a0400ebfd2318361c923a88103b2c67c49f",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6973a21ee73c5567f883813c8ef414774b45892f",
                    "status": "affected",
                    "version": "dd767856a36e00b631d65ebc4bb81b19915532d6",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/ipv6/xfrm6_output.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.2"
                  },
                  {
                    "lessThan": "3.2",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.10.*",
                    "status": "unaffected",
                    "version": "5.10.271",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "5.15.*",
                    "status": "unaffected",
                    "version": "5.15.222",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.1.*",
                    "status": "unaffected",
                    "version": "6.1.189",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.6.*",
                    "status": "unaffected",
                    "version": "6.6.158",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm: use full sockets in local error paths\n\nxfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb-\u003esk as if it\nalways pointed at a full IPv6 socket.\n\nThat is not guaranteed. TCP SYN-ACK skbs can be owned by a\nTCP_NEW_SYN_RECV request_sock while the output path itself is driven by the\nfull listener. If rerouting selects an IPv6 XFRM tunnel route with a lower\nMTU, the local PMTU/error handling path can reach these callbacks with that\nmini-socket still attached to the skb.\n\nThe callbacks then miscast the request socket as a full inet/IPv6 socket and\ncan read beyond the request_sock allocation when they access inet_sock or\nipv6_pinfo state.\n\nResolve the owner with skb_to_full_sk() in both callbacks and bail out when\nno full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error\nlogic, which already reasons about full sockets with skb_to_full_sk()."
          }
        ],
        "id": "CVE-2026-98241",
        "lastModified": "2026-10-07T07:17:05.957",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:12.090",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-08T16:49:34Z",
      "cve": "CVE-2026-98241",
      "id": "CVE-2026-98241",
      "initial_release_date": "2026-10-08T16:49:34Z",
      "product_status:known_affected": "297",
      "product_status:known_not_affected": "50",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98241",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98241.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…