Executive brief
The Linux kernel's xfrm (IPsec transform) subsystem contains a memory safety flaw in the selector matching logic that can cause a shift-out-of-bounds error. An attacker could exploit this to crash the kernel or potentially execute arbitrary code by crafting malformed IPsec selectors with invalid prefix lengths. This affects any system using IPsec networking, including VPN servers and security gateways.
Technical details
The vulnerability is a shift-out-of-bounds error in xfrm_selector_match() triggered when an AF_UNSPEC (unspecified address family) selector with an oversized prefixlen (e.g., 128 bits) is matched against an IPv4 flow when XFRM_STATE_AF_UNSPEC is set. The root cause is insufficient validation of the prefixlen parameter before it is used in bitshift operations. The fix adds three validation checks: rejecting mismatched address families in xfrm_selector_match(), returning false in addr4_match() if prefixlen exceeds 32 bits, and returning false in addr_match() if prefixlen exceeds 128 bits. The vulnerability requires network-level access to craft malicious IPsec packets or local access to invoke xfrm APIs with invalid parameters. Patches are available in the upstream Linux kernel and stable branches.
Affected products
- Linux Linux kernel All versions with xfrm subsystem; patches applied in 2026-06 onwards
Timeline
- 2026-08-15: disclosed: CVE-2026-72450 published
- 2026-06-15: patched: Upstream fix by Eric Dumazet committed
- 2026-07-24: patched: Backported to stable kernels