Re: [PATCH 6.1.y] xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

Sasha Levin <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Fri, Aug 21, 2026 at 12:42:00AM -0400, Artem Dinaburg wrote:
> Please queue this unchanged upstream fix for CVE-2026-64581 in 6.1.y. An
> unprivileged namespace user can race UDP transmit with per-socket XFRM policy
> replacement and double-release the cached destination.

Queued for 6.18, 6.12, 6.6, 6.1, 5.15 and 5.10, thanks.

-- 
Thanks,
Sasha
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.