Junglewise Threat Intelligence

CVE-2026-31406: Linux Kernel use-after-free in xfrm_nat_keepalive_net_fini

CVE-2026-31406 · Severity: high · CVSS 7.8 · Published 2026-04-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs during the cleanup of network resources, where a background task is incorrectly restarted after it should have been stopped. This leads to a 'use-after-free' condition where the system attempts to access memory that has already been released, impacting system stability and security.

Technical details

A race condition exists in the XFRM (IPsec) subsystem of the Linux kernel within the xfrm_nat_keepalive_net_fini() function. When a network namespace is being destroyed, the kernel attempts to cancel the NAT keepalive background work; however, subsequent state flushing can inadvertently re-schedule this work. This results in the background task running against a 'net' structure that has already been freed (use-after-free). An attacker with local access could exploit this race to cause a kernel panic or achieve privilege escalation. The fix replaces cancel_delayed_work_sync() with disable_delayed_work_sync() to ensure the work cannot be re-queued during the teardown process.

Affected products

  • Linux Linux Kernel 6.11 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc5

Timeline

  • 2026-03-11: other: Patch authored
  • 2026-04-06: advisory: CVE published

References

Related threats