SB20260720333 - Double free in Linux kernel xfrm
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-63911)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in the iptfs state cloning logic in net/xfrm/xfrm_iptfs.c when destroying a cloned security association after a failed state migration. A local user can trigger state migration failure and queued packet handling to cause a denial of service.
The issue can involve shared cloned runtime objects, including queue, timer, lock, and reassembly or reorder state copied from the original security association.
Remediation
Install update from vendor's website.