
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98370 is a use-after-free vulnerability in the Linux kernel's xfrm (IPsec transform) subsystem, specifically in the handling of compat ALLOCSPI requests. The flaw was published on October 6, 2026, and affects Linux kernel versions starting from 5.10 up to the patched stable releases. Fixed versions include 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4. The CVSS base score is currently listed as 0.0 (pending full scoring), though Feedly estimates the severity as HIGH (GitHub Advisory, Feedly).
The root cause is a use-after-free (CWE-416) triggered by a redundant compat conversion in xfrm_alloc_userspi(). When handling a compat ALLOCSPI request, xfrm_state_netlink() already calls alloc_compat() via dump_one_state() to build the response. However, xfrm_alloc_userspi() then calls alloc_compat() a second time on the original request skb, causing the translator to misinterpret the 228-byte compat xfrm_userspi_info structure as the 232-byte native layout — reading four bytes past the declared payload boundary. The incorrectly translated child is then published to the request's frag_list, which is shared with multicast clones of the skb. When xfrm_user_rcv_msg() frees the request after the handler returns, a compat receiver may still be copying from the translated child, creating a race condition and use-after-free. The fix removes the redundant alloc_compat() call in xfrm_alloc_userspi() (GitHub Advisory, Kernel Announce).
Successful exploitation allows a local attacker with access to netlink sockets to read out-of-bounds kernel memory (four bytes past the compat structure boundary) and exploit the use-after-free condition to potentially execute arbitrary code in kernel context. This could lead to full system compromise, privilege escalation to root, or kernel crash (denial of service). The vulnerability affects the confidentiality, integrity, and availability of the system, with the most severe outcome being local privilege escalation (Feedly, GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability requires local access to netlink sockets, which limits the attack surface compared to remote vulnerabilities. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting the current absence of observed exploitation (GitHub Advisory).
Update the Linux kernel to a patched stable version: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, or 7.3-rc4 and later. The fix removes the redundant alloc_compat() call in xfrm_alloc_userspi(), ensuring the response retains its correct compat translation from dump_one_state() without attaching a child to the inbound request. As a workaround where patching is not immediately possible, restrict unprivileged access to netlink sockets using mandatory access control frameworks such as SELinux, AppArmor, or seccomp policies (GitHub Advisory, Kernel Announce).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."