Executive brief
A vulnerability was identified in the Linux kernel's IPsec (XFRM) subsystem specifically affecting the IPTFS (IP Traffic Flow Security) mode. This component is responsible for securing network traffic by hiding packet sizes and timing. An exploit could lead to a system crash or unpredictable behavior due to improper handling of internal memory when network security settings are updated or migrated.
Technical details
A vulnerability in net/xfrm/xfrm_iptfs.c arises from iptfs_clone_state() using kmemdup() to copy IPTFS mode data without properly resetting runtime-specific fields. This results in the sharing of sensitive objects like sk_buff_head, hrtimers, and spinlocks between the original and cloned Security Association (SA). If xfrm_state_migrate() fails, the garbage collection task may destroy the cloned state using stale pointers from the original SA, leading to use-after-free or double-free conditions during skb release or state destruction. The fix involves explicitly reinitializing the clone's runtime state and managing module references before publishing the mode data.
Affected products
- Linux Linux Kernel 6.14, 6.18.35, 7.0.12
Timeline
- 2026-07-19: advisory: CVE-2026-63911 published by NVD
- 2026-05-26: patched: Fix committed to stable kernel tree