PT-2026-61189 · Linux · Linux
CVE-2026-63872
·
Publicado
2026-07-19
·
Atualizado
2026-07-19
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
In the Linux kernel, the following vulnerability has been resolved:
esp: fix page frag reference leak on skb to sgvec failure
In esp output tail(), when esp->inplace is false, the old skb page frags
are replaced with a new page from the xfrm page frag cache. The source
scatterlist (sg) is built from the old frags before the replacement, and
esp ssg unref() is responsible for releasing the old page references
after the crypto operation completes.
However, if the second skb to sgvec() call (which builds the destination
scatterlist from the new page) fails, the code jumps to error free which
only calls kfree(tmp). The old page frag references captured in the
source scatterlist are never released:
- sg[] is built from old frags via skb to sgvec() (no extra get page)
- nr frags is set to 1 and frag[0] is replaced with the new page
- Second skb to sgvec() fails -> goto error free
- kfree(tmp) frees the sg[] memory but old frags are not unref'd
- kfree skb() only releases frag[0] (the new page), not the old ones
Fix this by adding a bool parameter to esp ssg unref() that, when true,
unconditionally unrefs the source scatterlist frags without checking
req->src and req->dst, since those fields are not yet initialized by
aead request set crypt() at the point of the error. Existing callers
pass false to preserve the original behavior.
The same issue exists in both esp4 and esp6 as the code is identical.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux