
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98368 is a use-after-free and memory leak vulnerability in the Linux kernel's ESP (Encapsulating Security Payload) implementation, specifically in the out-of-place output path's handling of zerocopy managed socket buffer (SKB) fragments. The flaw was published on October 6, 2026, and affects Linux kernel versions from 6.0 onward, with fixes backported to stable releases 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4. Feedly estimates the severity as Medium (GitHub Advisory, Feedly).
The root cause is improper reference counting management (related to CWE-416, Use After Free) in the ESP out-of-place output path (esp->inplace == false). When an SKB carries zerocopy managed frags (SKBFL_MANAGED_FRAG_REFS), the payload frags are owned by the user buffer (ubuf) and must not be individually referenced or unreferenced. However, esp_ssg_unref() drops a page reference for every frag including ubuf-owned ones, pushing their refcount below the GUP pin bias while pages remain pinned (use-after-free); simultaneously, esp_output_tail() installs a destination page as frag 0 via get_page() but leaves SKBFL_MANAGED_FRAG_REFS set, causing skb_release_data() to skip the reference drop and leak the x->xfrag page at packet rate. The fix calls skb_zcopy_downgrade_managed() before ESP touches the frag array — consistent with how __ip_append_data(), __ip6_append_data(), and tcp_sendmsg_locked() handle the same scenario — taking real references on each existing frag and clearing the managed flag (GitHub Advisory).
A local user with access to zerocopy-enabled socket options (e.g., UDP_SEGMENT or similar) can trigger use-after-free of GUP-pinned memory pages and cause persistent memory leaks at packet rate. The primary consequences are denial of service through memory exhaustion or kernel crashes, and potential information disclosure via access to freed memory pages. The vulnerability is confined to systems using ESP (IPsec) with zerocopy networking, limiting its scope to specific network configurations (Feedly, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability requires local access and the ability to send network packets using zerocopy socket options, which limits the attack surface. It is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported (Feedly, GitHub Advisory).
dmesg / /var/log/kern.log) showing repeated warnings or BUG traces related to page refcount underflow, use-after-free, or KASAN/KFENCE reports involving ESP or zerocopy SKB paths.MemAvailable declining steadily without corresponding process growth.UDP_SEGMENT or zerocopy socket options on systems with active ESP/IPsec tunnels.Apply the available kernel patches backported to stable branches: 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4. The fix commits are available at the kernel stable tree (e.g., 0d0845ee61c5, 2359264f377c, 6508304ac2c8, 69a768c1239, 6cab554f2c0f, f89416eb3db1). As a temporary workaround where patching is not immediately possible, restrict or disable zerocopy socket options for applications using ESP/IPsec tunnels, or disable the out-of-place ESP output path if operationally feasible (GitHub Advisory, Kernel Announcement).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."