{
  "id": "CVE-2026-98370",
  "url": "https://spydr.io/cve/CVE-2026-98370",
  "published": "2026-10-06T09:18:31.450Z",
  "modified": "2026-10-06T09:18:31.450Z",
  "score": null,
  "severity": null,
  "cvss_version": null,
  "vector": null,
  "score_source": null,
  "epss": 0.00172,
  "epss_percentile": 0.05936,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": null,
  "vendors": [
    "Linux"
  ],
  "products": [
    "Linux"
  ],
  "cwes": [],
  "description": "In the Linux kernel, the following vulnerability has been resolved: xfrm: fix compat ALLOCSPI request use-after-free xfrm_state_netlink() builds the ALLOCSPI response with dump_one_state(), which already calls alloc_compat() with the response skb and header. xfrm_alloc_userspi() then calls alloc_compat() again, but passes the original request skb and its header. For a compat request, the translator therefore interprets the 228-byte compat xfrm_userspi_info as the 232-byte native layout and reads four bytes past the declared payload. It also publishes the translated child through the request's frag_list. A multicast clone of the request shares skb_shared_info and can observe that child. xfrm_user_rcv_msg() frees it after the request handler returns, racing a compat receiver which may still be copying from it and resulting in a use-after-free. Remove the redundant conversion. The response keeps its correct compat translation from dump_one_state(), and no child is attached to the inbound request.",
  "status": "Received",
  "score_type": null,
  "scores": {
    "cvss_v40": null,
    "cvss_v31": null,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/17893987e52918c23945c42e47e894a936305a25",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/248433942155b42a0ef04a5806c8aca024ea7c33",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/2b63341e2ebc9b6f73cbd9214dbe7d46dd98c718",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/42971ea17c7a8afc0bdd5ca40648bf4e5bb7b810",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/494f2bee9d8d0ebcfa249ac41bed7fed26d119b4",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/bb63ab52a18273ec68340ac49aebbaa7b514ccd5",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/d1ebd9081879fd9ae9c8fb7e8928f19cc88ae320",
      "tags": []
    },
    {
      "url": "https://git.kernel.org/stable/c/e70f639aee2ff0def155c256cace9e0f81d998e2",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98370",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
