KernelScan.io

CRITICAL

xfrm DirectOutput DoubleFree

CVE-2026-92489

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().

02

Engine v0.6.0

Risk summary

A double-free in the IPsec packet offload TX path can be triggered by a local user who has configured an XFRM tunnel in packet offload mode and sends a packet that netfilter drops. The resulting heap corruption can lead to kernel memory read/write primitives or a kernel panic. Products acting as IPsec VPN endpoints with packet offload-capable hardware are at risk, particularly those allowing unprivileged local code execution.

Affectednet/xfrm/xfrm_output.c (xfrm)

Vulnerability analysis

In the IPsec packet offload transmit path, when the network stack hands a packet to the local output function, a return value other than 1 indicates the packet buffer was already consumed or its ownership was transferred (for example, when netfilter drops the packet). The original code nevertheless freed the buffer on this error path, causing a double-free and invalidating any other owner of the buffer. The fix removes the redundant free and returns the error directly, matching the ownership semantics already used in the standard XFRM output path. The vulnerable code is reachable from a local process that can configure an XFRM state in packet offload mode — which requires CAP_NET_ADMIN, obtainable inside a user namespace by an unprivileged user — and then send a packet through the tunnel that triggers a netfilter drop.

03

BranchIntroducedFixed inPatch commit
6.126.12.216.12.110bc9297796bfd
mainline—7.3-rc1—
6.136.13.96.1402deb637e965
6.66.6.856.6.157621871b696b1
7.2—7.2.62aed51fc58d9
6.18—6.18.5256a347950e66