CVE-2026-72137: Double Free in Linux Kernel XFRM NAT Keepalive
Vulnerability ID: CVE-2026-72137
CVSS Score: 9.8
Published: 2026-08-15
CVE-2026-72137 is a critical double-free vulnerability in the Linux kernel's XFRM (IPsec) subsystem. The vulnerability occurs when the kernel attempts to send NAT keepalive packets over UDP. Under specific transmission failure conditions, both the downstream networking stack and the upstream keepalive dispatcher attempt to free the same socket buffer (sk_buff) structure, leading to kernel memory corruption, denial of service, or potential local privilege escalation.
TL;DR
A double-free vulnerability in the Linux kernel XFRM subsystem allows error-handling paths to release a socket buffer twice, causing kernel crashes or potential local privilege escalation.
Technical Details
- CWE ID: CWE-415 (Double Free)
- Attack Vector: Network (AV:N)
- CVSS Score: 9.8 (Critical)
- EPSS Score: 0.00671 (Percentile: 50.32%)
- Exploit Status: None (No public exploit available)
- KEV Status: Not Listed
Affected Systems
- Linux Kernel versions 6.11 through 6.12.100
- Linux Kernel versions 6.13 through 6.18.39
- Linux Kernel versions 6.19 through 7.1.4
-
Linux Kernel: [6.11.0, 6.12.101) (Fixed in:
6.12.101) -
Linux Kernel: [6.13.0, 6.18.40) (Fixed in:
6.18.40) -
Linux Kernel: [6.19.0, 7.1.5) (Fixed in:
7.1.5)
Code Analysis
Commit: 226f4a4
xfrm: nat_keepalive: avoid double free on send error (mainline patch)
Commit: d0a4dc7
xfrm: nat_keepalive: avoid double free on send error (backport)
Mitigation Strategies
- Upgrade the Linux kernel to patched versions (6.12.101, 6.18.40, 7.1.5, or higher).
- Disable UDP encapsulation of IPsec (NAT-Traversal) if not required, to prevent NAT keepalive generation.
- Restrict the CAP_NET_ADMIN capability for untrusted local users and containers to block route and interface manipulation.
Remediation Steps:
- Identify the running kernel version using 'uname -r'.
- Apply updates from your distribution's package manager to acquire the patched kernel version.
- Reboot the host to apply the new kernel.
- Verify that XFRM NAT keepalives are disabled or running on a patched kernel.
References
Read the full report for CVE-2026-72137 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)