CVE-2026-43091
In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit xfrm_policy_fini() frees the policy_bydst hash tables after flushing the policy work items and deleting all policies, but it does not…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit xfrm_policy_fini() frees the policy_bydst hash tables after flushing the policy work items and deleting all policies, but it does not wait for concurrent RCU readers to leave their read-side critical sections first. The policy_bydst tables are published via rcu_assign_pointer() and are looked up through rcu_dereference_check(), so netns teardown must also wait for an RCU grace period before freeing the table memory. Fix this by adding synchronize_rcu() before freeing the policy hash tables.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/069daad4f2ae9c5c108131995529d5f02392c446Patch
- https://git.kernel.org/stable/c/33a3149dd81a1e2f52b80ee1e0fc380b39f3d028Patch
- https://git.kernel.org/stable/c/3733fce2871c9bca9dd18a1a23b1432ea215a094Patch
- https://git.kernel.org/stable/c/438b1f668ad58f46ce699bb48e4698a7839e3f9ePatch
- https://git.kernel.org/stable/c/b66920a3348c0f63ba18365248fa21fbf0b3a937Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.