Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64581— xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

AI Predicted 7.8 Difficulty: Moderate EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1135 · Network Share Discovery

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux2b06cdf3e688b98fcc9945873b5d42792bd4eee0< 96b678d08268b5f5c6fc99d4289d9b7e334fc683affected
2b06cdf3e688b98fcc9945873b5d42792bd4eee0< c283e9ada7fcb7dd4b10592623086b2e6d2f9925affected
72f157be2f81910ae759bfe2e5c2256fc4625645affected
9e9fe58a92a46c6d154d2901735bf230d91b8507affected
adc1ec6cdc20d430aa01b86497220709b9149466affected
b54033eb1cfd77aba471269ddd804ed8d3e35deaaffected
c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04aaffected
5eef9b51114fcc65651d671add52f267f91b9451affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64581

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于xfrm_user_policy()清除socket dst cache时存在双重释放,可能导致释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 2b06cdf3e688b98fcc9945873b5d42792bd4eee0 ~ 96b678d08268b5f5c6fc99d4289d9b7e334fc683 -
LinuxLinux 4.14 -

II. Public POCs for CVE-2026-64581

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64581

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64581 (2)

Same Patch Batch · Linux · 2026-08-05 · 17 CVEs total

CVE-2026-64582RDMA/rxe: Fix a use-after-free problem in rxe_mmap
CVE-2026-64580xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
CVE-2026-64578ksmbd: validate compound request size before reading StructureSize2
CVE-2026-64579xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
CVE-2026-64576nexthop: initialize extack in nh_res_bucket_migrate()
CVE-2026-64577gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
CVE-2026-64575bpf: tcp: fix double sock release on batch realloc
CVE-2026-64573Bluetooth: qca: fix NVM tag length underflow in TLV parser
CVE-2026-64574wifi: mac80211: tear down new links on vif update error path
CVE-2026-64572ipv4: fib: free fib_alias with kfree_rcu() on insert error path
CVE-2026-64571wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVE-2026-64570wifi: mac80211: fix fils_discovery double free on alloc failure
CVE-2026-64569mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
CVE-2026-64568wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
CVE-2026-64567btrfs: reject free space cache with more entries than pages
CVE-2026-64566xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()

IV. Related Vulnerabilities

V. Comments for CVE-2026-64581

No comments yet


Leave a comment