xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()

Summary

CVECVE-2026-98369
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:31 UTC
Updated2026-10-07 07:17:11 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() syzbot reported a suspicious RCU usage warning in ip6_pkt_drop(): WARNING: suspicious RCU usage in ip6_pkt_drop include/net/addrconf.h:389 suspicious rcu_dereference_check() usage! Call Trace: __in6_dev_get_safely include/net/addrconf.h:389 [inline] ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620 ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651 xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806 process_one_work kernel/workqueue.c:3322 [inline] process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405 worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486 When commit 4f4920669d21 ("xfrm: Reinject transport-mode packets through workqueue") converted xfrm_trans_reinject from a tasklet to a workqueue, the reinjection loop ceased running in softirq context. Workqueue workers run in process context where local_bh_disable() does not enter an RCU read-side critical section under CONFIG_PREEMPT_RCU. Because finish callbacks (such as ip6_rcv_finish) expect to run under an RCU read lock (performing route lookups, l3mdev lookups, and accessing RCU-protected data structures), invoking them in workqueue context without rcu_read_lock() triggers RCU lockdep warnings. Furthermore, packets queued to the workqueue via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref). Additionally, on netdevice unregistration, dst_dev_put() replaces dst->dev with blackhole_netdev, so dst entries do not keep skb->dev alive while queued in the workqueue. Fix these issues by: 1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the caller's RCU section to ensure dst is reference-counted before queuing. 2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue deferral so skb->dev remains valid during finish() callback processing. 3. Acquiring rcu_read_lock() around the finish callback invocation loop in xfrm_trans_reinject().

Risk And Classification

Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.001800000 probability, percentile 0.069570000 (date 2026-10-06)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 7d98b26684cb2390729525b341ea099f0badbe18 41e47f1664be86c91326f0afe0504a1162d00907 git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 6601d91a85761f33351c71e04ec0bbd294ca07ce git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 0cda8273265d30cac6423834fd7d4acb75f04fdb git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 68a317b4aec8ca1868a39d69e40f9e29baa4f40a git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 6eb3b071be8e260543c604550c54dac66e6b174b git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 664fc0941df7c1918b2cd4de6ee00469ba77d8e4 git Not specified
CNA Linux Linux affected 4f4920669d21e1060b7243e5118dc3b71ced1276 d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 git Not specified
CNA Linux Linux affected f520075da484306bbb8425afd2c42404ba74816f git Not specified
CNA Linux Linux affected 130d9e5017ade1b81d16783563edb38c12a2eab7 git Not specified
CNA Linux Linux affected 5.15.75 5.15.222 semver Not specified
CNA Linux Linux affected 5.19.17 5.20 semver Not specified
CNA Linux Linux affected 6.0.3 6.1 semver Not specified
CNA Linux Linux affected 6.1 Not specified
CNA Linux Linux unaffected 6.1 semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/6eb3b071be8e260543c604550c54dac66e6b174b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/41e47f1664be86c91326f0afe0504a1162d00907 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d2f5082f9e84653fa1a9e8aebaaff23e688f5e19 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/664fc0941df7c1918b2cd4de6ee00469ba77d8e4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/68a317b4aec8ca1868a39d69e40f9e29baa4f40a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0cda8273265d30cac6423834fd7d4acb75f04fdb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6601d91a85761f33351c71e04ec0bbd294ca07ce 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report