{"id":"CVE-2026-98369","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n\nsyzbot reported a suspicious RCU usage warning in ip6_pkt_drop():\n\n  WARNIN…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n\nsyzbot reported a suspicious RCU usage warning in ip6_pkt_drop():\n\n  WARNIN…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 7d98b26684cb2390729525b341ea099f0badbe18 < 41e47f1664be86c91326f0afe0504a1162d00907","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < 6601d91a85761f33351c71e04ec0bbd294ca07ce","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < 0cda8273265d30cac6423834fd7d4acb75f04fdb","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < 68a317b4aec8ca1868a39d69e40f9e29baa4f40a","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < 6eb3b071be8e260543c604550c54dac66e6b174b","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < 664fc0941df7c1918b2cd4de6ee00469ba77d8e4","Linux >= 4f4920669d21e1060b7243e5118dc3b71ced1276 < d2f5082f9e84653fa1a9e8aebaaff23e688f5e19","Linux f520075da484306bbb8425afd2c42404ba74816f","Linux 130d9e5017ade1b81d16783563edb38c12a2eab7","Linux >= 5.15.75 < 5.15.222","Linux >= 5.19.17 < 5.20","Linux >= 6.0.3 < 6.1","Linux 6.1"],"published":"2026-10-06","updated":"2026-10-07","sourceUpdated":"2026-10-07T07:17:11.410","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98369","references":[{"url":"https://git.kernel.org/stable/c/0cda8273265d30cac6423834fd7d4acb75f04fdb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/41e47f1664be86c91326f0afe0504a1162d00907","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6601d91a85761f33351c71e04ec0bbd294ca07ce","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/664fc0941df7c1918b2cd4de6ee00469ba77d8e4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68a317b4aec8ca1868a39d69e40f9e29baa4f40a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6eb3b071be8e260543c604550c54dac66e6b174b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2f5082f9e84653fa1a9e8aebaaff23e688f5e19","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.0018,"epssPercentile":0.06957,"ingestedAt":"2026-10-06T08:50:17.392Z","slug":"CVE-2026-98369","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject()\n\nsyzbot reported a suspicious RCU usage warning in ip6_pkt_drop():\n\n  WARNING: suspicious RCU usage in ip6_pkt_drop\n  include/net/addrconf.h:389 suspicious rcu_dereference_check() usage!\n\n  Call Trace:\n   __in6_dev_get_safely include/net/addrconf.h:389 [inline]\n   ip6_pkt_drop+0x596/0x610 net/ipv6/route.c:4620\n   ip6_pkt_discard+0x1c/0x30 net/ipv6/route.c:4651\n   xfrm_trans_reinject+0x324/0x630 net/xfrm/xfrm_input.c:806\n   process_one_work kernel/workqueue.c:3322 [inline]\n   process_scheduled_works+0xa8e/0x14e0 kernel/workqueue.c:3405\n   worker_thread+0xa47/0xfb0 kernel/workqueue.c:3486\n\nWhen commit 4f4920669d21 (\"xfrm: Reinject transport-mode packets through\nworkqueue\") converted xfrm_trans_reinject from a tasklet to a workqueue,\nthe reinjection loop ceased running in softirq context. Workqueue workers\nrun in process context where local_bh_disable() does not enter an RCU\nread-side critical section under CONFIG_PREEMPT_RCU.\n\nBecause finish callbacks (such as ip6_rcv_finish) expect to run under an\nRCU read lock (performing route lookups, l3mdev lookups, and accessing\nRCU-protected data structures), invoking them in workqueue context without\nrcu_read_lock() triggers RCU lockdep warnings.\n\nFurthermore, packets queued to the workqueue via xfrm_trans_queue_net()\nmay carry non-refcounted (noref) dst entries (e.g. from ip_route_input_noref).\nAdditionally, on netdevice unregistration, dst_dev_put() replaces dst->dev\nwith blackhole_netdev, so dst entries do not keep skb->dev alive while\nqueued in the workqueue.\n\nFix these issues by:\n1. Calling skb_dst_force(skb) in xfrm_trans_queue_net() while still in the\n   caller's RCU section to ensure dst is reference-counted before queuing.\n2. Holding a reference on skb->dev via dev_hold()/dev_put() across workqueue\n   deferral so skb->dev remains valid during finish() callback processing.\n3. Acquiring rcu_read_lock() around the finish callback invocation loop in\n   xfrm_trans_reinject().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217359,"id":"CVE-2026-98369","ts":1791361319057,"field":"cvss","old":null,"new":"7.8"},{"seq":217358,"id":"CVE-2026-98369","ts":1791361319057,"field":"severity","old":"none","new":"high"}]}