CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of network namespaces during deferred transport reinjection, where a struct net pointer may become invalid if the namespace is torn down before the callback executes. This can lead to potential denial-of-service conditions or other unexpected behaviors in network operations. Organizations using Linux systems, especially those relying on advanced networking features, should prioritize addressing this issue to ensure the stability and security of their network infrastructure.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until the deferred callback runs. Take a netns reference when queueing deferred reinjection work and drop it after the callback completes. Use maybe_get_net() so the queueing path does not revive a namespace that is already being torn down. This keeps the existing workqueue design and fixes the netns lifetime handling in one place for all users of xfrm_trans_queue_net().