Back

MEDIUM

xfrm: fix refcount leak in __xfrm_policy_check()

Published Jun 18, 2025

Description

The issue happens on an error path in __xfrm_policy_check(). When the fetching process of the object `pols[1]` fails, the function simply returns 0, forgetting to decrement the reference count of `pols[0]`, which is incremented earlier by either xfrm_sk_policy_lookup() or xfrm_policy_lookup(). This may result in memory leaks.

Fix it by decreasing the reference count of `pols[0]` in that path.

Affected products

Remediation

Red Hat statement

This issue has been fixed in Red Hat Enterprise Linux 8.8 and 9.2 via RHSA-2023:2951 [1] and RHSA-2023:2458 [2], respectively. [1]. https://access.redhat.com/errata/RHSA-2023:2951 [2]. https://access.redhat.com/errata/RHSA-2023:2458

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jun 18, 2025
Updated May 11, 2026
Reserved Jun 18, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 18, 2025