{"id":"CVE-2026-64581","summary":"xfrm: fix sk_dst_cache double-free in xfrm_user_policy()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -\u003e sk_dst_check -\u003e sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged.","modified":"2026-10-09T18:26:44.014453095Z","published":"2026-08-05T08:09:35.556Z","related":["SUSE-SU-2026:23477-1","SUSE-SU-2026:23481-1","SUSE-SU-2026:23528-1","SUSE-SU-2026:23529-1","SUSE-SU-2026:23881-1","SUSE-SU-2026:23887-1","SUSE-SU-2026:23897-1","SUSE-SU-2026:23902-1","SUSE-SU-2026:4120-1","SUSE-SU-2026:4254-1","SUSE-SU-2026:4279-1","SUSE-SU-2026:4282-1","SUSE-SU-2026:4284-1","SUSE-SU-2026:4347-1","SUSE-SU-2026:4369-1","SUSE-SU-2026:4595-1","openSUSE-SU-2026:11476-1","openSUSE-SU-2026:21910-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64581.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0ea8f06454012d9e7f9c6e6253df710949bf6294"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8dd8929b71c4f06c614f8f54c2cc070453faae16"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e8686fd8d18b99f3a9038683045b2f2338a7706d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f0ab9a71167bae308e05ab13b65e2007504a603f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f833821e4b52ab6335d443ede5fb79c38e61d19a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64581.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64581"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"2b06cdf3e688b98fcc9945873b5d42792bd4eee0"},{"fixed":"e8686fd8d18b99f3a9038683045b2f2338a7706d"},{"fixed":"a9340ebdc13f8bb5063c0bc0b037ee7e640d4ae9"},{"fixed":"f833821e4b52ab6335d443ede5fb79c38e61d19a"},{"fixed":"f0ab9a71167bae308e05ab13b65e2007504a603f"},{"fixed":"8dd8929b71c4f06c614f8f54c2cc070453faae16"},{"fixed":"0ea8f06454012d9e7f9c6e6253df710949bf6294"},{"fixed":"96b678d08268b5f5c6fc99d4289d9b7e334fc683"},{"fixed":"c283e9ada7fcb7dd4b10592623086b2e6d2f9925"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3.16.52"},{"fixed":"3.17"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.4.163"},{"fixed":"4.5"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3.18.101"},{"fixed":"3.19"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.1.52"},{"fixed":"4.2"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.4.123"},{"fixed":"4.5"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"4.9.89"},{"fixed":"4.10"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"72f157be2f81910ae759bfe2e5c2256fc4625645"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"9e9fe58a92a46c6d154d2901735bf230d91b8507"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"adc1ec6cdc20d430aa01b86497220709b9149466"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"b54033eb1cfd77aba471269ddd804ed8d3e35dea"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"5eef9b51114fcc65651d671add52f267f91b9451"}]}],"versions":["v3.16.85","v3.16.84","v3.16.83","v3.16.82","v3.16.81","v3.16.80","v3.16.79","v3.16.78","v3.16.77","v3.16.76","v3.16.75","v3.16.74","v3.16.73","v3.16.72","v3.16.71","v3.16.70","v3.16.69","v3.16.68","v3.16.67","v3.16.66","v3.16.65","v3.16.64","v3.16.63","v3.16.62","v3.16.61","v3.16.60","v3.16.59","v3.16.58","v3.16.57","v3.16.56","v3.16.55","v3.16.54","v3.16.53","v3.16.52","v4.4.302","v4.4.301","v4.4.300","v4.4.299","v4.4.298","v4.4.297","v4.4.296","v4.4.295","v4.4.294","v4.4.293","v4.4.292","v4.4.291","v4.4.290","v4.4.289","v4.4.288","v4.4.287","v4.4.286","v4.4.285","v4.4.284","v4.4.283","v4.4.282","v4.4.281","v4.4.280","v4.4.279","v4.4.278","v4.4.277","v4.4.276","v4.4.275","v4.4.274","v4.4.273","v4.4.272","v4.4.271","v4.4.270","v4.4.269","v4.4.268","v4.4.267","v4.4.266","v4.4.265","v4.4.264","v4.4.263","v4.4.262","v4.4.261","v4.4.260","v4.4.259","v4.4.258","v4.4.257","v4.4.256","v4.4.255","v4.4.254","v4.4.253","v4.4.252","v4.4.251","v4.4.250","v4.4.249","v4.4.248","v4.4.247","v4.4.246","v4.4.245","v4.4.244","v4.4.243","v4.4.242","v4.4.241","v4.4.240","v4.4.239","v4.4.238","v4.4.237","v4.4.236","v4.4.235","v4.4.234","v4.4.233","v4.4.232","v4.4.231","v4.4.230","v4.4.229","v4.4.228","v4.4.227","v4.4.226","v4.4.225","v4.4.224","v4.4.223","v4.4.222","v4.4.221","v4.4.220","v4.4.219","v4.4.218","v4.4.217","v4.4.216","v4.4.215","v4.4.214","v4.4.213","v4.4.212","v4.4.211","v4.4.210","v4.4.209","v4.4.208","v4.4.207","v4.4.206","v4.4.205","v4.4.204","v4.4.203","v4.4.202","v4.4.201","v4.4.200","v4.4.199","v4.4.198","v4.4.197","v4.4.196","v4.4.195","v4.4.194","v4.4.193","v4.4.192","v4.4.191","v4.4.190","v4.4.189","v4.4.188","v4.4.187","v4.4.186","v4.4.185","v4.4.184","v4.4.183","v4.4.182","v4.4.181","v4.4.180","v4.4.179","v4.4.178","v4.4.177","v4.4.176","v4.4.175","v4.4.174","v4.4.173","v4.4.172","v4.4.171","v4.4.170","v4.4.169","v4.4.168","v4.4.167","v4.4.166","v4.4.165","v4.4.164","v4.4.163","v3.18.140","v3.18.139","v3.18.138","v3.18.137","v3.18.136","v3.18.135","v3.18.134","v3.18.133","v3.18.132","v3.18.131","v3.18.130","v3.18.129","v3.18.128","v3.18.127","v3.18.126","v3.18.125","v3.18.124","v3.18.123","v3.18.122","v3.18.121","v3.18.120","v3.18.119","v3.18.118","v3.18.117","v3.18.116","v3.18.115","v3.18.114","v3.18.113","v3.18.112","v3.18.111","v3.18.110","v3.18.109","v3.18.108","v3.18.107","v3.18.106","v3.18.105","v3.18.104","v3.18.103","v3.18.102","v3.18.101","v4.1.52","v4.4.162","v4.4.161","v4.4.160","v4.4.159","v4.4.158","v4.4.157","v4.4.156","v4.4.155","v4.4.154","v4.4.153","v4.4.152","v4.4.151","v4.4.150","v4.4.149","v4.4.148","v4.4.147","v4.4.146","v4.4.145","v4.4.144","v4.4.143","v4.4.142","v4.4.141","v4.4.140","v4.4.139","v4.4.138","v4.4.137","v4.4.136","v4.4.135","v4.4.134","v4.4.133","v4.4.132","v4.4.131","v4.4.130","v4.4.129","v4.4.128","v4.4.127","v4.4.126","v4.4.125","v4.4.124","v4.4.123","v4.9.337","v4.9.336","v4.9.335","v4.9.334","v4.9.333","v4.9.332","v4.9.331","v4.9.330","v4.9.329","v4.9.328","v4.9.327","v4.9.326","v4.9.325","v4.9.324","v4.9.323","v4.9.322","v4.9.321","v4.9.320","v4.9.319","v4.9.318","v4.9.317","v4.9.316","v4.9.315","v4.9.314","v4.9.313","v4.9.312","v4.9.311","v4.9.310","v4.9.309","v4.9.308","v4.9.307","v4.9.306","v4.9.305","v4.9.304","v4.9.303","v4.9.302","v4.9.301","v4.9.300","v4.9.299","v4.9.298","v4.9.297","v4.9.296","v4.9.295","v4.9.294","v4.9.293","v4.9.292","v4.9.291","v4.9.290","v4.9.289","v4.9.288","v4.9.287","v4.9.286","v4.9.285","v4.9.284","v4.9.283","v4.9.282","v4.9.281","v4.9.280","v4.9.279","v4.9.278","v4.9.277","v4.9.276","v4.9.275","v4.9.274","v4.9.273","v4.9.272","v4.9.271","v4.9.270","v4.9.269","v4.9.268","v4.9.267","v4.9.266","v4.9.265","v4.9.264","v4.9.263","v4.9.262","v4.9.261","v4.9.260","v4.9.259","v4.9.258","v4.9.257","v4.9.256","v4.9.255","v4.9.254","v4.9.253","v4.9.252","v4.9.251","v4.9.250","v4.9.249","v4.9.248","v4.9.247","v4.9.246","v4.9.245","v4.9.244","v4.9.243","v4.9.242","v4.9.241","v4.9.240","v4.9.239","v4.9.238","v4.9.237","v4.9.236","v4.9.235","v4.9.234","v4.9.233","v4.9.232","v4.9.231","v4.9.230","v4.9.229","v4.9.228","v4.9.227","v4.9.226","v4.9.225","v4.9.224","v4.9.223","v4.9.222","v4.9.221","v4.9.220","v4.9.219","v4.9.218","v4.9.217","v4.9.216","v4.9.215","v4.9.214","v4.9.213","v4.9.212","v4.9.211","v4.9.210","v4.9.209","v4.9.208","v4.9.207","v4.9.206","v4.9.205","v4.9.204","v4.9.203","v4.9.202","v4.9.201","v4.9.200","v4.9.199","v4.9.198","v4.9.197","v4.9.196","v4.9.195","v4.9.194","v4.9.193","v4.9.192","v4.9.191","v4.9.190","v4.9.189","v4.9.188","v4.9.187","v4.9.186","v4.9.185","v4.9.184","v4.9.183","v4.9.182","v4.9.181","v4.9.180","v4.9.179","v4.9.178","v4.9.177","v4.9.176","v4.9.175","v4.9.174","v4.9.173","v4.9.172","v4.9.171","v4.9.170","v4.9.169","v4.9.168","v4.9.167","v4.9.166","v4.9.165","v4.9.164","v4.9.163","v4.9.162","v4.9.161","v4.9.160","v4.9.159","v4.9.158","v4.9.157","v4.9.156","v4.9.155","v4.9.154","v4.9.153","v4.9.152","v4.9.151","v4.9.150","v4.9.149","v4.9.148","v4.9.147","v4.9.146","v4.9.145","v4.9.144","v4.9.143","v4.9.142","v4.9.141","v4.9.140","v4.9.139","v4.9.138","v4.9.137","v4.9.136","v4.9.135","v4.9.134","v4.9.133","v4.9.132","v4.9.131","v4.9.130","v4.9.129","v4.9.128","v4.9.127","v4.9.126","v4.9.125","v4.9.124","v4.9.123","v4.9.122","v4.9.121","v4.9.120","v4.9.119","v4.9.118","v4.9.117","v4.9.116","v4.9.115","v4.9.114","v4.9.113","v4.9.112","v4.9.111","v4.9.110","v4.9.109","v4.9.108","v4.9.107","v4.9.106","v4.9.105","v4.9.104","v4.9.103","v4.9.102","v4.9.101","v4.9.100","v4.9.99","v4.9.98","v4.9.97","v4.9.96","v4.9.95","v4.9.94","v4.9.93","v4.9.92","v4.9.91","v4.9.90","v4.9.89"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64581.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.14.0"},{"fixed":"5.10.267"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.218"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.185"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.154"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.106"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.47"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64581.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}