
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98369 is a Linux kernel vulnerability in the XFRM (IPsec) subsystem involving missing RCU read-side locking, skb_dst_force() calls, and device hold operations in the xfrm_trans_reinject() function. The flaw was introduced when commit 4f4920669d21 converted xfrm_trans_reinject from a tasklet to a workqueue handler without adding the necessary RCU protections. Affected versions include Linux kernel 5.15.75–5.15.221, 5.19.17–5.19.x, 6.0.3–6.0.x, and 6.1.x up to 6.1.188. The vulnerability was published on October 6, 2026, with patches available the same day. Feedly estimates the severity as Medium (GitHub Advisory, Feedly).
The root cause is a missing RCU read-side critical section in xfrm_trans_reinject() after the function was migrated from softirq (tasklet) context to process context (workqueue). In process context, local_bh_disable() does not implicitly enter an RCU read-side critical section under CONFIG_PREEMPT_RCU, so finish callbacks like ip6_rcv_finish() — which perform route lookups and access RCU-protected data structures — are invoked without the required rcu_read_lock(), triggering RCU lockdep warnings (CWE not formally assigned). Additionally, packets queued via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries, and dst_dev_put() during netdevice unregistration can replace dst->dev with blackhole_netdev, leaving skb->dev as a stale reference during workqueue processing. The fix adds skb_dst_force() before queuing, dev_hold()/dev_put() around workqueue deferral, and rcu_read_lock() around the finish callback loop (GitHub Advisory).
Successful exploitation can cause kernel RCU usage warnings, kernel oops, or use-after-free conditions, leading to system crashes or unpredictable kernel behavior — a Denial of Service impact. A local user with the ability to send crafted IPsec transport-mode packets can trigger these conditions by causing xfrm_trans_reinject() to access unprotected RCU data structures and stale device references. There is no evidence of confidentiality or integrity impact beyond kernel stability (Feedly, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the publication date. The vulnerability requires local access to send crafted IPsec transport-mode packets, limiting the attack surface. No EPSS score or CISA KEV catalog entry has been reported for this CVE (Feedly, GitHub Advisory).
dmesg / /var/log/kern.log) entries containing WARNING: suspicious RCU usage in ip6_pkt_drop or suspicious rcu_dereference_check() usage originating from include/net/addrconf.h:389.xfrm_trans_reinject, ip6_pkt_drop, ip6_pkt_discard, process_one_work, or worker_thread in close succession.Upgrade to a patched Linux kernel version: 5.15.222 or later (5.15.x series), 6.1.189 or later (6.1.x series), 6.6.158 or later (6.6.x series), 6.12.112 or later (6.12.x series), 6.18.54 or later (6.18.x series), or 7.2.8 or later. The patch adds rcu_read_lock() around the finish callback loop in xfrm_trans_reinject(), calls skb_dst_force() in xfrm_trans_queue_net() before queuing, and adds dev_hold()/dev_put() to keep skb->dev valid during workqueue deferral. No configuration-based workaround is documented; upgrading to a fixed kernel version is the recommended remediation (GitHub Advisory, Kernel Announcement).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."