CVE-2026-98370: 
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-98370 is a use-after-free vulnerability in the Linux kernel's xfrm (IPsec transform) subsystem, specifically in the handling of compat ALLOCSPI requests. The flaw was published on October 6, 2026, and affects Linux kernel versions starting from 5.10 up to the patched stable releases. Fixed versions include 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, and 7.3-rc4. The CVSS base score is currently listed as 0.0 (pending full scoring), though Feedly estimates the severity as HIGH (GitHub Advisory, Feedly).

Technical details

The root cause is a use-after-free (CWE-416) triggered by a redundant compat conversion in xfrm_alloc_userspi(). When handling a compat ALLOCSPI request, xfrm_state_netlink() already calls alloc_compat() via dump_one_state() to build the response. However, xfrm_alloc_userspi() then calls alloc_compat() a second time on the original request skb, causing the translator to misinterpret the 228-byte compat xfrm_userspi_info structure as the 232-byte native layout — reading four bytes past the declared payload boundary. The incorrectly translated child is then published to the request's frag_list, which is shared with multicast clones of the skb. When xfrm_user_rcv_msg() frees the request after the handler returns, a compat receiver may still be copying from the translated child, creating a race condition and use-after-free. The fix removes the redundant alloc_compat() call in xfrm_alloc_userspi() (GitHub Advisory, Kernel Announce).

Impact

Successful exploitation allows a local attacker with access to netlink sockets to read out-of-bounds kernel memory (four bytes past the compat structure boundary) and exploit the use-after-free condition to potentially execute arbitrary code in kernel context. This could lead to full system compromise, privilege escalation to root, or kernel crash (denial of service). The vulnerability affects the confidentiality, integrity, and availability of the system, with the most severe outcome being local privilege escalation (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability requires local access to netlink sockets, which limits the attack surface compared to remote vulnerabilities. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting the current absence of observed exploitation (GitHub Advisory).

Mitigation and workarounds

Update the Linux kernel to a patched stable version: 5.10.271, 5.15.222, 6.1.189, 6.6.158, 6.12.112, 6.18.54, 7.2.8, or 7.3-rc4 and later. The fix removes the redundant alloc_compat() call in xfrm_alloc_userspi(), ensuring the response retains its correct compat translation from dump_one_state() without attaching a child to the inbound request. As a workaround where patching is not immediately possible, restrict unprivileged access to netlink sockets using mandatory access control frameworks such as SELinux, AppArmor, or seccomp policies (GitHub Advisory, Kernel Announce).

Additional resources


Source: This report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98372NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98371NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98370NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98369NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026
CVE-2026-98368NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management