{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-68420",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-30T09:28:09.392Z",
        "datePublished": "2026-08-10T12:04:40.933Z",
        "dateUpdated": "2026-08-17T05:05:15.432Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T05:05:15.432Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: reject optional IPTFS templates in outbound policies\n\nsyzbot reported a stack-out-of-bounds read in xfrm_state_find()\nwhich flows from xfrm_tmpl_resolve_one().\n\nCommit 3d776e31c841 (\"xfrm: Reject optional tunnel/BEET mode\ntemplates in outbound policies\") disallowed optional tunnel and\nBEET in outbound policies to prevent this. Later when IPTFS\nadded, it was not covered by that fix and can still trigger\nthe out-of-bounds read;\n\nExtend the check to disallow optional IPTFS in outbound policies\nas well. IPTFS should be identical to tunnel mode.\nIN and FWD policies are not affected: xfrm_tmpl_resolve_one()\nis only reachable via the outbound path.\n\nReproducer, before:\n\nip link add dummy0 type dummy\nip link set dummy0 up\nip addr add 10.1.1.1/24 dev dummy0\nip xfrm policy add src 10.1.1.1/32 dst 10.1.1.2/32 dir out tmpl\n  src fc00::dead:1 dst fc00::dead:2 proto esp reqid 1 mode iptfs\n  level use tmpl src fc00::dead:1 dst fc00::dead:2 proto esp reqid\n  2 mode transport\nping -W 1 -c 1 10.1.1.2\nPING 10.1.1.2 (10.1.1.2) 56(84) bytes of data.\n\n[   64.168420] ==================================================================\n[   64.169977] BUG: KASAN: stack-out-of-bounds in __xfrm6_addr_hash+0x11e/0x170\n[   64.169977] Read of size 4 at addr ffff88800e1ffd20 by task ping/2844\n\n[   64.169977] CPU: 2 UID: 0 PID: 2844 Comm: ping Not tainted 7.1.0-rc7-00180-geb23b588430a #98 PREEMPT(full)\n[   64.169977] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[   64.169977] Call Trace:\n[   64.169977]  <TASK>\n[   64.169977]  dump_stack_lvl+0x47/0x70\n[   64.169977]  ? __xfrm6_addr_hash+0x11e/0x170\n[   64.169977]  print_report+0x152/0x4b0\n[   64.169977]  ? ksys_mmap_pgoff+0x6d/0xa0\n[   64.169977]  ? entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[   64.169977]  ? rcu_read_unlock_sched+0xa/0x20\n[   64.169977]  ? __virt_addr_valid+0x21b/0x230\n[   64.169977]  ? __xfrm6_addr_hash+0x11e/0x170\n[   64.169977]  kasan_report+0xa8/0xd0\n[   64.169977]  ? __xfrm6_addr_hash+0x11e/0x170\n[   64.169977]  __xfrm6_addr_hash+0x11e/0x170\n[   64.169977]  __xfrm_dst_hash+0x24/0xc0\n[   64.169977]  xfrm_state_find+0xa2d/0x2f90\n[   64.169977]  ? __pfx_xfrm_state_find+0x10/0x10\n[   64.169977]  ? __pfx_ftrace_graph_ret_addr+0x10/0x10\n[   64.169977]  ? __pfx_ftrace_graph_ret_addr+0x10/0x10\n[   64.169977]  xfrm_tmpl_resolve_one+0x210/0x570\n[   64.169977]  ? __pfx_xfrm_tmpl_resolve_one+0x10/0x10\n[   64.169977]  ? __pfx_stack_trace_consume_entry+0x10/0x10\n[   64.169977]  ? kernel_text_address+0x5b/0x80\n[   64.169977]  ? __kernel_text_address+0xe/0x30\n[   64.169977]  ? unwind_get_return_address+0x5e/0x90\n[   64.169977]  ? arch_stack_walk+0x8c/0xe0\n[   64.169977]  xfrm_tmpl_resolve+0x130/0x200\n[   64.169977]  ? __pfx_xfrm_tmpl_resolve+0x10/0x10\n[   64.169977]  ? __pfx_xfrm_policy_inexact_lookup_rcu+0x10/0x10\n[   64.169977]  ? __refcount_add_not_zero.constprop.0+0xb2/0x110\n[   64.169977]  ? __pfx___refcount_add_not_zero.constprop.0+0x10/0x10\n[   64.169977]  xfrm_resolve_and_create_bundle+0xd5/0x310\n[   64.169977]  ? __pfx_xfrm_resolve_and_create_bundle+0x10/0x10\n[   64.169977]  ? __pfx_xfrm_policy_lookup_bytype+0x10/0x10\n[   64.169977]  ? __pfx_xfrm_policy_lookup_bytype+0x10/0x10\n[   64.169977]  xfrm_lookup_with_ifid+0x3d8/0xb80\n[   64.169977]  ? __pfx_xfrm_lookup_with_ifid+0x10/0x10\n[   64.169977]  ? ip_route_output_key_hash+0xc6/0x110\n[   64.169977]  ? kasan_save_track+0x10/0x30\n[   64.169977]  xfrm_lookup_route+0x18/0xe0\n[   64.169977]  ip4_datagram_release_cb+0x4c9/0x530\n[   64.169977]  ? __pfx_ip4_datagram_release_cb+0x10/0x10\n[   64.169977]  ? do_raw_spin_lock+0x71/0xc0\n[   64.169977]  ? __pfx_do_raw_spin_lock+0x10/0x10\n[   64.169977]  release_sock+0xb0/0x170\n[   64.169977]  udp_connect+0x43/0x50\n[   64.169977]  __sys_connect+0xa6/0x100\n[   64.169977]  ? alloc_fd+0x2e9/0x300\n[   64.169977]  ? __pfx___sys_connect+0x10/0x10\n[   64.169977]  ? preempt_latency\n---truncated---"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The attacker must install an XFRM policy over the AF_KEY/XFRM netlink socket and then originate local traffic (connect()/sendto()) matching that policy, so the entire path requires local access to the machine; no remote packet reaches this code.\nAC:L - The reproducer is deterministic — add one outbound policy with an optional IPTFS template plus a following transport-mode template of a different family, then send one packet; no race, no memory-layout dependence, and CONFIG_XFRM is enabled on all mainstream distros.\nPR:L - xfrm_user_rcv_msg() checks netlink_net_capable(CAP_NET_ADMIN), which resolves to ns_capable(net->user_ns, CAP_NET_ADMIN); an unprivileged user obtains this with \"unshare -Urn\" and can create the dummy device, the policy, and the triggering traffic entirely inside that namespace.\nUI:N - The attacker performs every step — policy insertion and packet transmission — with no action by any other user or administrator.\nS:U - The out-of-bounds read stays within the kernel's own stack and the affected resources are managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - __xfrm6_addr_hash() reads 16 bytes from a 4-byte on-stack IPv4 address, exposing adjacent kernel stack contents; with zeroed template addresses xfrm_init_tempstate() copies those bytes into the acquire state, which is broadcast to userspace via XFRM_MSG_ACQUIRE, leaking kernel stack data (potentially pointers usable for KASLR defeat).\nI:N - The defect is purely a read of out-of-bounds stack memory; no kernel memory is written out of bounds and no control-flow or data structure is corrupted by the attacker.\nA:H - The invalid access is a KASAN-detected stack out-of-bounds read that taints the kernel and terminates the machine on kernels built with KASAN or panic_on_warn, and the bogus state derived from garbage addresses can be re-triggered at will by an unprivileged user."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/xfrm/xfrm_user.c"
                    ],
                    "versions": [
                        {
                            "version": "d1716d5a44c37e5743bf6ea4e5cdbdab37727f27",
                            "lessThan": "d7fc6f351c478586980a521d63b0214d9c055e78",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d1716d5a44c37e5743bf6ea4e5cdbdab37727f27",
                            "lessThan": "9333f4b6f44858fc98eb12bf26b8d2959eb975d5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d1716d5a44c37e5743bf6ea4e5cdbdab37727f27",
                            "lessThan": "ea528f18231ec0f33317be57f8866913b19aba6e",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/xfrm/xfrm_user.c"
                    ],
                    "versions": [
                        {
                            "version": "6.14",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.14",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.42",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.6",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.14",
                                    "versionEndExcluding": "6.18.42"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.14",
                                    "versionEndExcluding": "7.1.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.14",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/d7fc6f351c478586980a521d63b0214d9c055e78"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9333f4b6f44858fc98eb12bf26b8d2959eb975d5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ea528f18231ec0f33317be57f8866913b19aba6e"
                }
            ],
            "title": "xfrm: reject optional IPTFS templates in outbound policies",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}