Linux Kernel Vulnerability in xfrm Module Introduces RCU Lock Issues
CVE-2026-98369
What is CVE-2026-98369?
A vulnerability in the Linux kernel's xfrm module has led to improper handling of RCU locks, resulting in warnings during the processing of network packets. This situation is triggered when the xfrm_trans_reinject function was transitioned from tasklet to workqueue, which eradicated the previous RCU context, leading to failures in maintaining necessary locks. Consequently, this introduced risks associated with processing packets that do not retain valid device references, potentially resulting in unexpected behavior and system instability. The issue has been addressed through implementing necessary RCU locking mechanisms and ensuring proper reference counting for packet destinations within the workqueue context.
Affected Version(s)
Linux 7d98b26684cb2390729525b341ea099f0badbe18 < 41e47f1664be86c91326f0afe0504a1162d00907
Linux 4f4920669d21e1060b7243e5118dc3b71ced1276 < 6601d91a85761f33351c71e04ec0bbd294ca07ce
Linux 4f4920669d21e1060b7243e5118dc3b71ced1276 < 0cda8273265d30cac6423834fd7d4acb75f04fdb