Linux Kernel XFRM MIGRATE Notification Routing Vulnerability

Vulnerability

A vulnerability in the Linux kernel's handling of XFRM_MSG_MIGRATE notifications has been identified. The issue arises because the migration notifications are hardcoded to the initial network namespace, rather than the namespace of the caller. This flaw affects the IKEv2 protocol's MOBIKE and address-update handling, particularly for daemons running in non-initial network namespaces.

Impact

The vulnerability disrupts the IKEv2 MOBIKE and address-update handling within a network namespace, causing migration notifications to be misrouted or not received at all.

Reproduction

To reproduce this vulnerability, an IKE daemon must be run in a non-initial network namespace and subscribed to its own XFRMNLGRP_MIGRATE or pfkey groups. The daemon will not receive notifications of its own migration, leading to a broken address-update handling.

Remediation

The vulnerability has been fixed in the Linux kernel. Users should upgrade to the latest version.

Added: Jul 19, 2026, 9:21 PM
Updated: Jul 19, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.4
exploitability
3.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.