Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially gain unauthorized access to data. The issue occurs when the system cleans up network namespaces, a feature used to isolate network traffic for containers or different services. If exploited, this could lead to a complete loss of system availability or a breach of sensitive information.
Technical details
A race condition exists in the XFRM subsystem of the Linux kernel during network namespace (netns) exit. The function xfrm_policy_fini() frees the policy_bydst hash tables without ensuring that concurrent RCU (Read-Copy-Update) readers have finished their read-side critical sections. Because these tables are accessed via rcu_dereference_check(), freeing the memory before an RCU grace period has elapsed can lead to a use-after-free scenario. A local attacker could potentially exploit this to cause a kernel panic (DoS) or achieve privilege escalation. The fix involves adding a synchronize_rcu() call to ensure all readers have exited before the memory is reclaimed.
Affected products
- Linux Linux Kernel 4.9 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7
Timeline
- 2026-05-06: advisory: Initial disclosure by kernel.org
- 2026-05-06: disclosed
- 2026-04-07: patched: Initial patch committed to stable tree
References
- https://git.kernel.org/stable/c/069daad4f2ae9c5c108131995529d5f02392c446
- https://git.kernel.org/stable/c/33a3149dd81a1e2f52b80ee1e0fc380b39f3d028
- https://git.kernel.org/stable/c/3733fce2871c9bca9dd18a1a23b1432ea215a094
- https://git.kernel.org/stable/c/438b1f668ad58f46ce699bb48e4698a7839e3f9e
- https://git.kernel.org/stable/c/b66920a3348c0f63ba18365248fa21fbf0b3a937