Executive brief
The Linux kernel's IPsec NAT keepalive mechanism contains a memory management bug that can cause a crash or potential code execution when network packets fail to send. The vulnerability occurs in the network stack's handling of socket buffers during error conditions, where memory can be freed twice. Systems running affected kernel versions with IPsec NAT keepalive functionality enabled are at risk of denial of service.
Technical details
The vulnerability is a use-after-free / double-free in the xfrm NAT keepalive implementation (kernel/net/xfrm/xfrm_nat_keepalive.c). The nat_keepalive_send() function incorrectly frees the socket buffer (skb) after handing it to ip_build_and_send_pkt() or ip6_xmit() in error paths; once these functions take ownership, the networking stack may consume the skb before returning an error, making a subsequent free unsafe. The fix relocates error-path cleanup into nat_keepalive_send_ipv4() and nat_keepalive_send_ipv6() where the caller retains ownership, ensuring cleanup happens only before handoff. The vulnerability requires NAT keepalive to be active (typically in ESP-in-UDP IPsec configurations) and is reachable from network-triggered packet transmission failures. Patches are available in commit 226f4a490d1a938fc838d8f8c46a4eca864c0d78 and upstream/stable branches.
Affected products
- Linux Linux kernel Multiple versions (2.6.x, 3.x, 4.x, 5.x, 6.x, 7.x affected; see stable branches)
Timeline
- 2026-06-25: disclosed: Patch authored by Qianyu Luo
- 2026-06-30: patched: Merged into linux stable (commit 226f4a490d1a938fc838d8f8c46a4eca864c0d78)
- 2026-07-24: patched: Backported to stable branches by Greg Kroah-Hartman
- 2026-08-15: advisory: Published on NVD