Executive brief
A performance issue in the Linux kernel's networking component can cause systems to run out of memory and crash when many network namespaces are created and destroyed. This occurs because the system handles internal cleanup tasks inefficiently, leading to a massive backlog of pending operations that consume all available system memory. This could result in a denial-of-service (DoS) where the server becomes unresponsive or reboots.
Technical details
A vulnerability in the XFRM (IPsec) subsystem of the Linux kernel arises from the improper use of synchronize_rcu() within the per-namespace .exit handler (xfrm_policy_fini). Because .exit handlers are executed serially for each namespace, a high rate of network namespace churn (e.g., unshare(CLONE_NEWNET)) causes the cleanup_net() queue to back up. This leads to a massive accumulation of 'struct net' objects and per-cpu memory usage, eventually triggering Out-Of-Memory (OOM) conditions. The fix involves moving the RCU synchronization logic from the .exit handler to the .pre_exit handler, allowing for batched grace periods and O(1) efficiency.
Affected products
- Linux Linux Kernel 6.12.83 to 6.12.93, 6.18
Timeline
- 2026-05-21: other: Patch authored
- 2026-07-25: advisory: CVE published