GHSA-x3mf-vgc4-phvgCriticalCVSS 9.8

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in...

Published
September 17, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Fix skb double-free in xfrm_dev_direct_output()

A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner.

Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().

🔗 References (7)