PT-2026-94459 · Linux · Linux Kernel
CVE-2026-90111
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A slab use-after-free occurs in the IPv6 multicast routing component. When an ingress multicast packet misses the Multicast Forwarding Cache (MFC) lookup, the
ip6mr cache unresolved() function places the socket buffer (skb) onto an unresolved queue, which allows it to escape the receive-side Read-Copy-Update (RCU) grace period. If the underlying route is deleted and freed, and the MFC queue is subsequently resolved with an incorrect parent interface, the ip6 mr forward() function calls ip6mr cache report() with the MRT6MSG WRONGMIF flag. This triggers the dst clone() function on the already freed destination (dst) entry. RCU is a synchronization mechanism that allows multiple readers to access data while a single writer modifies it.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel