PT-2026-85633 · Linux · Linux
CVE-2026-80792
·
Publicado
2026-09-04
·
Atualizado
2026-09-04
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix use-after-free in ip6 finish output2()
ip6 finish output2() caches a pointer to the IPv6 destination
address (daddr) before invoking lwtunnel xmit(). The LWT-BPF
transmit path or other encapsulation operations within
lwtunnel xmit() can reallocate the skb head, freeing the memory
that daddr points to. When lwtunnel xmit() returns
LWTUNNEL XMIT CONTINUE, the function continues to use the stale
daddr pointer to compute the nexthop and to look up or create the
neighbour entry. This results in a use-after-free read, which can
leak sensitive kernel data, pollute the neighbour table with
arbitrary values, misdirect traffic, or crash the system.
Fix this by re-fetching the IPv6 header and the destination
address pointer after lwtunnel xmit() returns
LWTUNNEL XMIT CONTINUE, ensuring that the subsequent nexthop
computation and neighbour lookup operate on valid memory.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux