CVE-2026-31663CWE-826

CVE-2026-31663

High · published April 24, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
2.4
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

xfrm: hold dev ref until after transport_finish NF_HOOK

After async crypto completes, xfrm_input_resume() calls dev_put()

immediately on re-entry before the skb reaches transport_finish.

The skb->dev pointer is then used inside NF_HOOK and its okfn,

which can race with device teardown.

Remove the dev_put from the async resumption entry and instead

drop the reference after the NF_HOOK call in transport_finish,

using a saved device pointer since NF_HOOK may consume the skb.

This covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip

the okfn.

For non-transport exits (decaps, gro, drop) and secondary

async return points, release the reference inline when

async is set.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00124 · 2.4th percentile
Weakness
CWE-826 · Premature Release of Resource During Expected Lifetime
Published
2026-04-24T19:16Z
Affected products (13)
ProductVersionsFixed in
linux/linux_kernel≥ 3.2.100, < 3.33.3
linux/linux_kernel≥ 3.16.55, < 3.173.17
linux/linux_kernel≥ 4.14.24, < 4.154.15
linux/linux_kernel≥ 4.15.1, < 6.18.236.18.23
linux/linux_kernel≥ 6.19, < 6.19.136.19.13
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
linux/linux_kernelall versions
References (7)
EPSS history
Timeline
  • 24 APR 14:45Z
    xfrm: hold dev ref until after transport_finish NF_HOOK
    cvelistv5