{"id":"CVE-2026-98229","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: save input state data before secpath resets\n\nxfrm_input() stores the current xfrm_state in the skb secpath while it\ncontinues receive-side processing","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: save input state data before secpath resets\n\nxfrm_input() stores the current xfrm_state in the skb secpath while it\ncontinues receive-side processing. Some input …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0 < 35de97850987b3d022ed17df5b2577242e746daf","Linux >= df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0 < 148db154066b066616b82c12d373e786eba1f96a","Linux >= df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0 < 537a5ae18b2be70f8eb0aca843682e81a69aab91","Linux >= df3893c176e9b0bb39b28ab5ec8113fa20ad1ee0 < 3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa","Linux 3.15"],"published":"2026-10-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T07:17:05.543","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98229","references":[{"url":"https://git.kernel.org/stable/c/148db154066b066616b82c12d373e786eba1f96a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35de97850987b3d022ed17df5b2577242e746daf","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3cf5cdecd99c9c186a5ea518d93bbf3045b6e3aa","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/537a5ae18b2be70f8eb0aca843682e81a69aab91","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00209,"epssPercentile":0.10066,"ingestedAt":"2026-10-06T08:50:17.438Z","slug":"CVE-2026-98229","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: save input state data before secpath resets\n\nxfrm_input() stores the current xfrm_state in the skb secpath while it\ncontinues receive-side processing. Some input paths can reset that secpath\nbefore xfrm_input() has finished dereferencing the state.\n\nReceive callback users such as VTI and XFRM interfaces can reset the\nsecpath. The VTI receive path does so before checking whether the packet\ncrosses network namespaces, while the XFRM interface path does so only for\ncross-network-namespace packets. The XFRM_MAX_DEPTH error path can also\nreset the secpath before the final drop callback reports the current\nstate's protocol.\n\nIf secpath_reset() drops the last state reference while the state is\nconcurrently deleted, xfrm_input() can still dereference the freed state\nwhen selecting transport_finish() or reporting the drop callback protocol.\n\nSave the state protocol on the stack while the state is still valid,\nand use the already saved address family for transport_finish(). A larval\nXFRM_STATE_ACQ state has no type, so retain nexthdr as its protocol. This\npreserves the existing drop-path fallback while avoiding the post-reset\nstate dereferences without adding an extra state reference to every\nreceived packet.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217278,"id":"CVE-2026-98229","ts":1791361305454,"field":"cvss","old":null,"new":"7.8"},{"seq":217277,"id":"CVE-2026-98229","ts":1791361305454,"field":"severity","old":"none","new":"high"}]}