Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs during the cleanup of network resources, where a background task is incorrectly restarted after it should have been stopped. This leads to a 'use-after-free' condition where the system attempts to access memory that has already been released, impacting system stability and security.
Technical details
A race condition exists in the XFRM (IPsec) subsystem of the Linux kernel within the xfrm_nat_keepalive_net_fini() function. When a network namespace is being destroyed, the kernel attempts to cancel the NAT keepalive background work; however, subsequent state flushing can inadvertently re-schedule this work. This results in the background task running against a 'net' structure that has already been freed (use-after-free). An attacker with local access could exploit this race to cause a kernel panic or achieve privilege escalation. The fix replaces cancel_delayed_work_sync() with disable_delayed_work_sync() to ensure the work cannot be re-queued during the teardown process.
Affected products
- Linux Linux Kernel 6.11 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11, 7.0-rc1 to 7.0-rc5
Timeline
- 2026-03-11: other: Patch authored
- 2026-04-06: advisory: CVE published