Use-After-Free Vulnerability in Linux Kernel Network Device Management
CVE-2026-98364

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98364?

A vulnerability in the Linux kernel arises from improper handling of network device references during bundle creation. Specifically, the functions xfrm_bundle_create() and xfrm_create_dummy_bundle() do not take a device reference when accessed, resulting in potential use-after-free conditions. When a concurrent RTM_DELLINK modifies dst->dev and frees the previous net_device, any subsequent references can lead to system crashes or exploits. The issue is primarily located within the xfrm6_fill_dst() function, where a stale device pointer may be dereferenced. The vulnerability has been addressed by adjusting the reference management process to ensure that the necessary device references are maintained through the respective critical section.

Affected Version(s)

Linux 25ee3286dcbc830a833354bb1d15567956844813 < 8d85d6bc9c46dc41cb2be0eac53f8ab068c3a807

Linux 25ee3286dcbc830a833354bb1d15567956844813 < 9fa903b24b1f46b4ff5443bcd4aca23e5c57f9c1

Linux 2.6.25

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.