CVE-2026-98369: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-98369 is a Linux kernel vulnerability in the XFRM (IPsec) subsystem involving missing RCU read-side locking, skb_dst_force() calls, and device hold operations in the xfrm_trans_reinject() function. The flaw was introduced when commit 4f4920669d21 converted xfrm_trans_reinject from a tasklet to a workqueue handler without adding the necessary RCU protections. Affected versions include Linux kernel 5.15.75–5.15.221, 5.19.17–5.19.x, 6.0.3–6.0.x, and 6.1.x up to 6.1.188. The vulnerability was published on October 6, 2026, with patches available the same day. Feedly estimates the severity as Medium (GitHub Advisory, Feedly).

Technical details

The root cause is a missing RCU read-side critical section in xfrm_trans_reinject() after the function was migrated from softirq (tasklet) context to process context (workqueue). In process context, local_bh_disable() does not implicitly enter an RCU read-side critical section under CONFIG_PREEMPT_RCU, so finish callbacks like ip6_rcv_finish() — which perform route lookups and access RCU-protected data structures — are invoked without the required rcu_read_lock(), triggering RCU lockdep warnings (CWE not formally assigned). Additionally, packets queued via xfrm_trans_queue_net() may carry non-refcounted (noref) dst entries, and dst_dev_put() during netdevice unregistration can replace dst->dev with blackhole_netdev, leaving skb->dev as a stale reference during workqueue processing. The fix adds skb_dst_force() before queuing, dev_hold()/dev_put() around workqueue deferral, and rcu_read_lock() around the finish callback loop (GitHub Advisory).

Impact

Successful exploitation can cause kernel RCU usage warnings, kernel oops, or use-after-free conditions, leading to system crashes or unpredictable kernel behavior — a Denial of Service impact. A local user with the ability to send crafted IPsec transport-mode packets can trigger these conditions by causing xfrm_trans_reinject() to access unprotected RCU data structures and stale device references. There is no evidence of confidentiality or integrity impact beyond kernel stability (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the publication date. The vulnerability requires local access to send crafted IPsec transport-mode packets, limiting the attack surface. No EPSS score or CISA KEV catalog entry has been reported for this CVE (Feedly, GitHub Advisory).

Indicators of compromise

  • Logs: Kernel log (dmesg / /var/log/kern.log) entries containing WARNING: suspicious RCU usage in ip6_pkt_drop or suspicious rcu_dereference_check() usage originating from include/net/addrconf.h:389.
  • Logs: Kernel stack traces referencing xfrm_trans_reinject, ip6_pkt_drop, ip6_pkt_discard, process_one_work, or worker_thread in close succession.
  • Process: Unexpected kernel oops or BUG messages associated with the XFRM or IPv6 routing subsystems following IPsec transport-mode packet processing.

Mitigation and workarounds

Upgrade to a patched Linux kernel version: 5.15.222 or later (5.15.x series), 6.1.189 or later (6.1.x series), 6.6.158 or later (6.6.x series), 6.12.112 or later (6.12.x series), 6.18.54 or later (6.18.x series), or 7.2.8 or later. The patch adds rcu_read_lock() around the finish callback loop in xfrm_trans_reinject(), calls skb_dst_force() in xfrm_trans_queue_net() before queuing, and adds dev_hold()/dev_put() to keep skb->dev valid during workqueue deferral. No configuration-based workaround is documented; upgrading to a fixed kernel version is the recommended remediation (GitHub Advisory, Kernel Announcement).

Additional resources


Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management