Answer in brief
CVE-2026-98230 records a Unknown severity vulnerability in xfrm: use hlist_del_init_rcu for state_cache and state_cache_input. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=aa48a18fdb0911572d133057cd579db704b87da4 <fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5 || >=0045e3d80613cc7174dc15f189ee6fc4e73b9365 <4748c27e2e6a1969e02f1df46e62f79d2799b80b || >=0045e3d80613cc7174dc15f189ee6fc4e73b9365 <9b74a47a4cbd0d29faff4f3b199212c73e6b6220 || >=0045e3d80613cc7174dc15f189ee6fc4e73b9365 <2afb8dc1f4390f164db8352f8e685e126e9db566 || 5e4334dc39443645415450163ff5ff1ee7e79784 || >=6.12.13 <6.12.112 | fb38fb7420d5f7192f9e2b6ac835ede149cd7ac5, 4748c27e2e6a1969e02f1df46e62f79d2799b80b, 9b74a47a4cbd0d29faff4f3b199212c73e6b6220, 2afb8dc1f4390f164db8352f8e685e126e9db566, 6.12.112 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: use hlist_del_init_rcu for state_cache and state_cache_input Commit 14acf9652e56 ("xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete") converted bydst/bysrc/byseq/byspi from hlist_del_rcu() to hlist_del_init_rcu() so that a second __xfrm_state_delete() on the same object becomes a no-op rather than a write through LIST_POISON pprev. It missed state_cache and state_cache_input, which kept hlist_del_rcu(): - hlist_del_rcu() leaves pprev = LIST_POISON2 (non-NULL), so hlist_unhashed() returns false. - hlist_del_init_rcu() leaves pprev = NULL, so hlist_unhashed() returns true. A second __xfrm_state_delete() therefore enters __hlist_del() on the already-deleted state_cache/state_cache_input nodes and does WRITE_ONCE(*pprev, next) through LIST_POISON2 — a write use-after-free once the slab is reused. The corruption can in turn cause a subsequent hlist_for_each_entry_rcu traversal to follow a dangling next pointer, producing the read use-after-free reported in xfrm_input_state_lookup(). Switch state_cache and state_cache_input to hlist_del_init_rcu() to match the other four lists, closing the write use-after-free and, with it, the read use-after-free it spawns.
Quoted source text, attributed separately from HOL analysis.