Bug 2492779 (CVE-2026-53239) - CVE-2026-53239 kernel: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
Summary: CVE-2026-53239 kernel: xfrm: policy: fix use-after-free on inexact bin in xfr...
Keywords:
Status: NEW
Alias: CVE-2026-53239
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-25 10:05 UTC by OSIDB Bzimport
Modified: 2026-10-05 00:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:67471 0 None None None 2026-09-15 06:14:29 UTC
Red Hat Product Errata RHSA-2026:68531 0 None None None 2026-09-17 07:20:50 UTC
Red Hat Product Errata RHSA-2026:68532 0 None None None 2026-09-17 06:56:55 UTC
Red Hat Product Errata RHSA-2026:68570 0 None None None 2026-09-17 12:15:53 UTC
Red Hat Product Errata RHSA-2026:74174 0 None None None 2026-10-01 09:01:40 UTC
Red Hat Product Errata RHSA-2026:75560 0 None None None 2026-10-05 00:36:08 UTC

Description OSIDB Bzimport 2026-06-25 10:05:18 UTC
In the Linux kernel, the following vulnerability has been resolved:

xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()

Fix the race by pruning the bin while still holding xfrm_policy_lock,
before dropping it. Use __xfrm_policy_inexact_prune_bin() directly since
the lock is already held. The wrapper xfrm_policy_inexact_prune_bin()
becomes unused and is removed.

Race:

  CPU0 (XFRM_MSG_DELPOLICY)           CPU1 (XFRM_MSG_NEWSPDINFO)
  ==========================          ==========================
  xfrm_policy_bysel_ctx():
    spin_lock_bh(xfrm_policy_lock)
    bin = xfrm_policy_inexact_lookup()
    __xfrm_policy_unlink(pol)
    spin_unlock_bh(xfrm_policy_lock)
    xfrm_policy_kill(ret)
    // wide window, lock not held
                                       xfrm_hash_rebuild():
                                         spin_lock_bh(xfrm_policy_lock)
                                         __xfrm_policy_inexact_flush():
                                           kfree_rcu(bin)  // bin freed
                                         spin_unlock_bh(xfrm_policy_lock)
    xfrm_policy_inexact_prune_bin(bin)
    // UAF: bin is freed

Comment 4 Jon Orris 2026-09-15 06:14:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67471 https://access.redhat.com/errata/RHSA-2026:67471

Comment 5 Jon Orris 2026-09-17 06:56:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:68532 https://access.redhat.com/errata/RHSA-2026:68532

Comment 6 Jon Orris 2026-09-17 07:20:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:68531 https://access.redhat.com/errata/RHSA-2026:68531

Comment 7 Jon Orris 2026-09-17 12:15:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:68570 https://access.redhat.com/errata/RHSA-2026:68570

Comment 8 Jon Orris 2026-10-01 09:01:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:74174 https://access.redhat.com/errata/RHSA-2026:74174

Comment 9 Jon Orris 2026-10-05 00:36:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:75560 https://access.redhat.com/errata/RHSA-2026:75560


Note You need to log in before you can comment on or make changes to this bug.