Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
CVSS Score
CRITICAL
References
- https://git.kernel.org/stable/c/02deb637e965950148752a304dd1471212dd6470
- https://git.kernel.org/stable/c/2aed51fc58d9ce450e2c116efb956160fd06fa02
- https://git.kernel.org/stable/c/56a347950e661c1a7f8f31c43a2ea53c2323b6f4
- https://git.kernel.org/stable/c/621871b696b108026bf4b44ed4085ffa2102f417
- https://git.kernel.org/stable/c/bc9297796bfdcc8d9609236e54519a4f38737aac
FAQ
What is CVE-2026-92489?
CVE-2026-92489 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been con...
How severe is CVE-2026-92489?
CVE-2026-92489 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-92489?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.