[PATCH ipsec v4 6/9] xfrm: fix hw offload state leak on xfrm_do_migrate_state() error path
From: Antony Antony
Date: Tue Oct 06 2026 - 03:08:53 EST
In the error path, the cloned state is dropped without removing its
hardware offload, leaking the offloaded SA entry.
Fixes: a9d155ea9b44 ("xfrm: add XFRM_MSG_MIGRATE_STATE for single SA migration")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Signed-off-by: Antony Antony <antony.antony@xxxxxxxxxxx>
---
net/xfrm/xfrm_user.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/xfrm/xfrm_user.c b/net/xfrm/xfrm_user.c
index 8640838dcda0..4de8c401eb44 100644
--- a/net/xfrm/xfrm_user.c
+++ b/net/xfrm/xfrm_user.c
@@ -3541,6 +3541,8 @@ static int xfrm_do_migrate_state(struct sk_buff *skb, struct nlmsghdr *nlh,
xfrm_state_put(x);
return err;
out_xc:
+ if (m.xuo)
+ xfrm_dev_state_delete(xc);
xc->km.state = XFRM_STATE_DEAD;
xfrm_state_put(xc);
xfrm_state_put(x);
--
2.47.3