CVE-2026-92489

Unknown

Last modified

CVE-2026-92489 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume()..

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= bfb9b9404a53a72524ce695551755117e9d3deb0, < 621871b696b108026bf4b44ed4085ffa2102f417; >= a0395e96831adee8ffa016bf958e4dce9ece656e, < bc9297796bfdcc8d9609236e54519a4f38737aac; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 02deb637e965950148752a304dd1471212dd6470; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 2aed51fc58d9ce450e2c116efb956160fd06fa02; d1d673a5bede3767252cff19c0ab1e5387c6f43f; >= 6.6.85, < 6.6.157; >= 6.12.21, < 6.12.110; >= 6.13.9, < 6.14
LinuxLinux6.14

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-92489?
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
How severe is CVE-2026-92489?
Severity scoring for CVE-2026-92489 is pending analysis.
How do I fix CVE-2026-92489?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-92489?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST