In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluster in the xfrm_state lifecycle, the load-bearing one being: BUG: KASAN: slab-use-after-free in __h…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/14acf9652e5690de3c7486c6db5fb8dafd0a32a3 Patch
- https://git.kernel.org/stable/c/26edb0a3c99f9d958c212be68b21f1221614dcf0 Patch
- https://git.kernel.org/stable/c/2c617848ae6e4f07a3e397f604208c293bbecacc Patch
- https://git.kernel.org/stable/c/3943fcad7694a7d0b15aeabe7d3cc2a2eb8e92e8 Patch
- https://git.kernel.org/stable/c/4980162de555cb838f1a189ce7d2cbf5d2e7b050 Patch
- https://git.kernel.org/stable/c/a2e2d08fb070fab4947447171f1c4e3ca5a188e5 Patch
- https://git.kernel.org/stable/c/b4a53add2fa8f1b5aa17d4c5686c320785fab182 Patch
- https://access.redhat.com/errata/RHSA-2026:36018
- https://access.redhat.com/errata/RHSA-2026:39179
- https://access.redhat.com/errata/RHSA-2026:39180
- https://access.redhat.com/errata/RHSA-2026:39371
- https://access.redhat.com/errata/RHSA-2026:41234
- https://access.redhat.com/errata/RHSA-2026:41235
- https://access.redhat.com/errata/RHSA-2026:42919
- https://access.redhat.com/errata/RHSA-2026:43231
- https://access.redhat.com/security/cve/CVE-2026-46116
- https://bugzilla.redhat.com/show_bug.cgi?id=2482523
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46116.json
Timeline
- nvd_ingest NVD