CVE-2026-92489
Last modified
CVE-2026-92489 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume()..
Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= bfb9b9404a53a72524ce695551755117e9d3deb0, < 621871b696b108026bf4b44ed4085ffa2102f417; >= a0395e96831adee8ffa016bf958e4dce9ece656e, < bc9297796bfdcc8d9609236e54519a4f38737aac; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 02deb637e965950148752a304dd1471212dd6470; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 56a347950e661c1a7f8f31c43a2ea53c2323b6f4; >= 5eddd76ec2fd1988f0a3450fde9730b10dd22992, < 2aed51fc58d9ce450e2c116efb956160fd06fa02; d1d673a5bede3767252cff19c0ab1e5387c6f43f; >= 6.6.85, < 6.6.157; >= 6.12.21, < 6.12.110; >= 6.13.9, < 6.14 |
| Linux | Linux | 6.14 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-92489?
How severe is CVE-2026-92489?
How do I fix CVE-2026-92489?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92483In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92484In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92485In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92486In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92487In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92488In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9249Unverified password change in Devolutions Server allows an a…3.1
- CVE-2026-92490In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92491In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92492In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92493In the Linux kernel, the following vulnerability has been re…
- CVE-2026-92494In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-92489?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
