ipv6: xfrm: use full sockets in local error paths

Summary

CVECVE-2026-98241
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:12 UTC
Updated2026-10-06 09:18:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm: use full sockets in local error paths xfrm6_local_rxpmtu() and xfrm6_local_error() dereference skb->sk as if it always pointed at a full IPv6 socket. That is not guaranteed. TCP SYN-ACK skbs can be owned by a TCP_NEW_SYN_RECV request_sock while the output path itself is driven by the full listener. If rerouting selects an IPv6 XFRM tunnel route with a lower MTU, the local PMTU/error handling path can reach these callbacks with that mini-socket still attached to the skb. The callbacks then miscast the request socket as a full inet/IPv6 socket and can read beyond the request_sock allocation when they access inet_sock or ipv6_pinfo state. Resolve the owner with skb_to_full_sk() in both callbacks and bail out when no full socket is attached. This matches the surrounding XFRM IPv6 PMTU/error logic, which already reasons about full sockets with skb_to_full_sk().

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 b1a88633c36d2cbc3831382f3846754d344276fd git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 904a0e827d0d7189271a3a2eb648293809f25efc git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 675919e08ce266b8cac11fd9af29170e762a480f git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 60459c670329d586a58db5d8f811fa5accfe4862 git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 ca3d68c3213475b53db6647e159dc73bd1af5ab1 git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 4c030a0400ebfd2318361c923a88103b2c67c49f git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8 git Not specified
CNA Linux Linux affected dd767856a36e00b631d65ebc4bb81b19915532d6 6973a21ee73c5567f883813c8ef414774b45892f git Not specified
CNA Linux Linux affected 3.2 Not specified
CNA Linux Linux unaffected 3.2 semver Not specified
CNA Linux Linux unaffected 5.10.271 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/c21f3f7fbfeda7c5794f606cb0ffcc2d9001eef8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ca3d68c3213475b53db6647e159dc73bd1af5ab1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/904a0e827d0d7189271a3a2eb648293809f25efc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b1a88633c36d2cbc3831382f3846754d344276fd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/60459c670329d586a58db5d8f811fa5accfe4862 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6973a21ee73c5567f883813c8ef414774b45892f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/4c030a0400ebfd2318361c923a88103b2c67c49f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/675919e08ce266b8cac11fd9af29170e762a480f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report