Answer in brief
CVE-2026-98370 records a Unknown severity vulnerability in xfrm: fix compat ALLOCSPI request use-after-free. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <494f2bee9d8d0ebcfa249ac41bed7fed26d119b4 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <17893987e52918c23945c42e47e894a936305a25 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <bb63ab52a18273ec68340ac49aebbaa7b514ccd5 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <248433942155b42a0ef04a5806c8aca024ea7c33 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <e70f639aee2ff0def155c256cace9e0f81d998e2 || >=5f3eea6b7e8f58cf5c8a9d4b9679dc19e9e67ba3 <d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 | 494f2bee9d8d0ebcfa249ac41bed7fed26d119b4, 17893987e52918c23945c42e47e894a936305a25, 42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810, 2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718, bb63ab52a18273ec68340ac49aebbaa7b514ccd5, 248433942155b42a0ef04a5806c8aca024ea7c33, e70f639aee2ff0def155c256cace9e0f81d998e2, d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.
Quoted source text, attributed separately from HOL analysis.