Junglewise Threat Intelligence

CVE-2026-43091: Linux Kernel use-after-free in XFRM policy netns exit

CVE-2026-43091 · Severity: high · CVSS 7.8 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially gain unauthorized access to data. The issue occurs when the system cleans up network namespaces, a feature used to isolate network traffic for containers or different services. If exploited, this could lead to a complete loss of system availability or a breach of sensitive information.

Technical details

A race condition exists in the XFRM subsystem of the Linux kernel during network namespace (netns) exit. The function xfrm_policy_fini() frees the policy_bydst hash tables without ensuring that concurrent RCU (Read-Copy-Update) readers have finished their read-side critical sections. Because these tables are accessed via rcu_dereference_check(), freeing the memory before an RCU grace period has elapsed can lead to a use-after-free scenario. A local attacker could potentially exploit this to cause a kernel panic (DoS) or achieve privilege escalation. The fix involves adding a synchronize_rcu() call to ensure all readers have exited before the memory is reclaimed.

Affected products

  • Linux Linux Kernel 4.9 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-05-06: advisory: Initial disclosure by kernel.org
  • 2026-05-06: disclosed
  • 2026-04-07: patched: Initial patch committed to stable tree

References

Related threats