From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1BCED3DAAA1 for ; Fri, 4 Sep 2026 16:00:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537636; cv=none; b=AfmTWD8IvYzbJnedvihhFBhkE/XtEtz9O4/eKDSvpcFPwlFuPlfBqUUx5p3B9qp5oWc89CyhMRpF0KdoJxZfKu6u2IjWkDEEz1qspZR1sbPTpwUbC2IpHogGQLPPAEEnBTNjj1gkz0V5YiX+a0IjuFDGjx//NjOOKgvHkzRjBbs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537636; c=relaxed/simple; bh=zE7w/njBtB/ghiEl0EGee/LURbTqly+U9j28GVLD8U0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=f+vJb+PF5LCUTETqK6zbgC1A5vZOaiVHwS2xsMHFUyqwGW/cRxy89wR8f1vD3du3OO/EyFrOPDr4iiiKrbTczEUZrKgIwRpR+Id8lYBYpyB5V/xJXAOFg9HBb611QP7NZbqoRCibAfAbv4NTdUjvyNA9X8ficcPE469JoafdoQo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=b+JJQb3t; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="b+JJQb3t" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 96E141F00A3D; Fri, 4 Sep 2026 16:00:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537635; bh=Ew6n1KgTUSKR743Pp53y1gkWUQEJDTVaQHqhI0lYHlE=; h=From:To:Cc:Subject:Date:Reply-To; b=b+JJQb3tOpoxArFMoHqqYxCLhQiRBfQNe96lK6udlXLwHc3Uo7oVL+ZNT1aBBFk0d Ll43HVzpUHF5KXdTPI823+VD/l5HDv6B7Hlc9k1Plhxz9IJqdwfBlxoUgevQ3Xiei6 RhXs76Y7VDfSxqjU6W+foEv8QFpmNbI4edliUd7U= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80848: xfrm: espintcp: fix UAF during close Date: Fri, 4 Sep 2026 17:53:15 +0200 Message-ID: <2026090459-CVE-2026-80848-3987@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4091; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=LdZHStbEWxF8GpWavwrGieEr9OqyoqJmNkTmsFDks4A=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXkZvPHT71qYvTQyO7y5fMJcKMftqdtWvx1EuTlPA4 7GCWNLnjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZgIz0qGBeea61/yn1Jy/sUt c0kk3Ied3zikjWGe1V3RoBsBl7uTPgipTav9m7NGR7cIAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race condition during close for espintcp sockets: espintcp_close() frees emsg->skb via kfree_skb() without holding any socket lock. Concurrently, the xfrm_trans_reinject work queue invokes esp_output_tcp_finish() -> espintcp_push_skb() -> espintcp_push_msgs() -> skb_send_sock_locked(), which reads the same skb as a data source. Fix this by adding a synchronize_rcu() call after resetting sk_prot, since esp_output_tcp_finish() runs under RCU and won't use a socket with sk_prot == &tcp_prot. Simply taking the socket lock in espintcp_close() could lead to leaks, if esp_output_tcp_finish() re-adds an skb in the slot we just freed. After this, the existing barrier() is no longer needed. The Linux kernel CVE team has assigned CVE-2026-80848 to this issue. Affected and fixed versions =========================== Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 5.10.269 with commit 29121c5e6591da527e8e36ddac7120dc527f574d Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 5.15.220 with commit ed5d9102190c45fc70121c036b0626b740040b75 Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 6.1.187 with commit 4bc0dfa28dca6fc0084203732695968049c44072 Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 6.6.156 with commit ff8dd7a932f34409a56e1b91a1219340f17457e9 Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 6.12.108 with commit 4b31a875693c480c611519faca46216514e3e052 Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 6.18.49 with commit 24efebecf415ba264adba0f0491cec436463a14f Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 7.1.13 with commit eb3bbf29c723fe75c0eb92be14f0ec92971fe272 Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 7.2.3 with commit 54b41ad14da9a981131ab6e4d3f79321a503ea5d Issue introduced in 5.6 with commit e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 and fixed in 7.3-rc1 with commit deb232e884877bf10b4ce2580909eedec986c284 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80848 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/xfrm/espintcp.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/29121c5e6591da527e8e36ddac7120dc527f574d https://git.kernel.org/stable/c/ed5d9102190c45fc70121c036b0626b740040b75 https://git.kernel.org/stable/c/4bc0dfa28dca6fc0084203732695968049c44072 https://git.kernel.org/stable/c/ff8dd7a932f34409a56e1b91a1219340f17457e9 https://git.kernel.org/stable/c/4b31a875693c480c611519faca46216514e3e052 https://git.kernel.org/stable/c/24efebecf415ba264adba0f0491cec436463a14f https://git.kernel.org/stable/c/eb3bbf29c723fe75c0eb92be14f0ec92971fe272 https://git.kernel.org/stable/c/54b41ad14da9a981131ab6e4d3f79321a503ea5d https://git.kernel.org/stable/c/deb232e884877bf10b4ce2580909eedec986c284