PT-2026-85633 · Linux · Linux

CVE-2026-80792

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix use-after-free in ip6 finish output2()
ip6 finish output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel xmit() returns LWTUNNEL XMIT CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system.
Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel xmit() returns LWTUNNEL XMIT CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80792

Produtos afetados

Linux