xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
Published Jun 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
Fix the race by pruning the bin while still holding xfrm_policy_lock, before dropping it. Use __xfrm_policy_inexact_prune_bin() directly since the lock is already held. The wrapper xfrm_policy_inexact_prune_bin() becomes unused and is removed.
Race:
CPU0 (XFRM_MSG_DELPOLICY) CPU1 (XFRM_MSG_NEWSPDINFO) ========================== ========================== xfrm_policy_bysel_ctx(): spin_lock_bh(xfrm_policy_lock) bin = xfrm_policy_inexact_lookup() __xfrm_policy_unlink(pol) spin_unlock_bh(xfrm_policy_lock) xfrm_policy_kill(ret) // wide window, lock not held xfrm_hash_rebuild(): spin_lock_bh(xfrm_policy_lock) __xfrm_policy_inexact_flush(): kfree_rcu(bin) // bin freed spin_unlock_bh(xfrm_policy_lock) xfrm_policy_inexact_prune_bin(bin) // UAF: bin is freed
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.0StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.0
- Version 5.10.259StatusunaffectedConstraints<=5.10.*
- Version 5.15.210StatusunaffectedConstraints<=5.15.*
- Version 6.1.176StatusunaffectedConstraints<=6.1.*
- Version 6.12.94StatusunaffectedConstraints<=6.12.*
- Version 6.18.36StatusunaffectedConstraints<=6.18.*
- Version 6.6.143StatusunaffectedConstraints<=6.6.*
- Version 7.0.13StatusunaffectedConstraints<=7.0.*
- Version 7.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.0 · < 5.10.259
- ≥ 5.11 · < 5.15.210
- ≥ 5.16 · < 6.1.176
- ≥ 6.2 · < 6.6.143
- ≥ 6.7 · < 6.12.94
- ≥ 6.13 · < 6.18.36
- ≥ 6.19 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-211.55.1.el10_2
Fixed · RHSA-2026:67471
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.164.1.el8_10
Fixed · RHSA-2026:68531
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.164.1.rt7.505.el8_10
Fixed · RHSA-2026:68532
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.49.1.el9_8
Fixed · RHSA-2026:68570
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.49.1.el9_8
Fixed · RHSA-2026:68570
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-211.55.1.el10_2 | Fixed | RHSA-2026:67471 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.164.1.el8_10 | Fixed | RHSA-2026:68531 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.164.1.rt7.505.el8_10 | Fixed | RHSA-2026:68532 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.49.1.el9_8 | Fixed | RHSA-2026:68570 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.49.1.el9_8 | Fixed | RHSA-2026:68570 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (15)
- https://access.redhat.com/security/cve/CVE-2026-53239 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492779 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39330 Advisory
- https://git.kernel.org/stable/c/25c8c7fb3b0b9668c7d05e209f58c158d2b020c7 Patch
- https://git.kernel.org/stable/c/42827d03f8009a6a218bacab153e21f39d6a121c Patch
- https://git.kernel.org/stable/c/7f2d76c9c03257c0782afef9d95321fa04096f60 Patch
- https://git.kernel.org/stable/c/88697cf980222d5906a37bf47662dac0732e2a0f Patch
- https://git.kernel.org/stable/c/8fc536e9f6856230f19c7d13e71af064b6a77b22 Patch
- https://git.kernel.org/stable/c/b5316e2b8614a87d8736941972441cb47bfd4491 Patch
- https://git.kernel.org/stable/c/c4c1ea36d83bf3c4569468ca5b8b614fda1bf821 Patch
- https://git.kernel.org/stable/c/ec82ea4eb220164d854f8734ca5a35e23e577b94 Patch
- https://lore.kernel.org/linux-cve-announce/2026062510-CVE-2026-53239-8ebc@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53239
- https://www.cve.org/CVERecord?id=CVE-2026-53239
Change history (0)
No recorded changes yet.