PT-2026-98604 · Linux · Linux
CVE-2026-97940
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix fib6 walker UAF on seq stop
ipv6 route iter active() treats a walker in FWS U at the table root as
already unlinked. fib6 del route() can move a still-linked walker into
that same state when the current leaf is the last route at the root,
so ipv6 route native seq stop() skips fib6 walker unlink(). The seq
private object can then be freed while it remains on
net->ipv6.fib6 walkers. A later route deletion walks the dangling list
and uses the freed walker.
Use the list head as membership state and reinitialize it when
unlinking. Keep the existing w->node check so a never-started iterator
with a zeroed private object is not treated as linked.
The same stop helper is used by /proc/net/ipv6 route and by the BPF
ipv6 route iterator. The BPF show path only widens the race.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux