CVE-2026-43091
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/05/2026
Last modified:
19/05/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
xfrm: Wait for RCU readers during policy netns exit<br />
<br />
xfrm_policy_fini() frees the policy_bydst hash tables after flushing the<br />
policy work items and deleting all policies, but it does not wait for<br />
concurrent RCU readers to leave their read-side critical sections first.<br />
<br />
The policy_bydst tables are published via rcu_assign_pointer() and are<br />
looked up through rcu_dereference_check(), so netns teardown must also<br />
wait for an RCU grace period before freeing the table memory.<br />
<br />
Fix this by adding synchronize_rcu() before freeing the policy hash tables.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.9 (including) | 6.6.136 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/069daad4f2ae9c5c108131995529d5f02392c446
- https://git.kernel.org/stable/c/33a3149dd81a1e2f52b80ee1e0fc380b39f3d028
- https://git.kernel.org/stable/c/3733fce2871c9bca9dd18a1a23b1432ea215a094
- https://git.kernel.org/stable/c/438b1f668ad58f46ce699bb48e4698a7839e3f9e
- https://git.kernel.org/stable/c/b66920a3348c0f63ba18365248fa21fbf0b3a937



