CVE-2026-92489: Linux
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume().
Affected products
- Linux Linux: from 6.6.85, before 6.6.157 (fixed in 6.6.157); from 6.12.21, before 6.12.110 (fixed in 6.12.110); from 6.13.9, before 6.14 (fixed in 6.14); from 6.14, before 6.18.52 (fixed in 6.18.52); from 6.19, before 7.2.6 (fixed in 7.2.6)
Published 2026-09-17. Last modified 2026-09-18.