PT-2026-94459 · Linux · Linux Kernel

CVE-2026-90111

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab use-after-free occurs in the IPv6 multicast routing component. When an ingress multicast packet misses the Multicast Forwarding Cache (MFC) lookup, the ip6mr cache unresolved() function places the socket buffer (skb) onto an unresolved queue, which allows it to escape the receive-side Read-Copy-Update (RCU) grace period. If the underlying route is deleted and freed, and the MFC queue is subsequently resolved with an incorrect parent interface, the ip6 mr forward() function calls ip6mr cache report() with the MRT6MSG WRONGMIF flag. This triggers the dst clone() function on the already freed destination (dst) entry. RCU is a synchronization mechanism that allows multiple readers to access data while a single writer modifies it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102087
CVE-2026-90111
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel