CVE-2026-74581
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6 rule result
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info.
If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release().
Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 209d35ee34e25f9668c404350a1c86d914c54ffa < 90c57310e266eb94e4a80d6b15a9ca131d2e82cb | affected |
| Linux | Linux | 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383 < 5d29b286c9de0b309e94b9ed083aa1a2f429434f | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < 354db6243eca59e9d187ffbf8b7955b044ce84dc | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < 6d98c70fe0ba8c7708bfd5b2a5174d2086775daa | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < 9bad152c42b37499162367fe47867411e62fffa3 | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < dc3ab04220667f254f4348572b2a0b3febff89fb | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < a341c091ca0bfae377747b1b59a3bd8ebe18a937 | affected |
| Linux | Linux | cdef485217d30382f3bf6448c54b4401648fe3f1 < 6aea62e433fe1b586202a5fee8b5807ce635e1d7 | affected |
| Linux | Linux | ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29 | affected |
| Linux | Linux | 5.10.84 < 5.10.265 | affected |
| Linux | Linux | 5.15.7 < 5.15.216 | affected |
| Linux | Linux | 5.4.164 < 5.5 | affected |
| Linux | Linux | 5.16 | affected |
| Linux | Linux | 0 < 5.16 | unaffected |
| Linux | Linux | 5.10.265 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.216 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.183 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.151 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.103 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.44 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.8 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb
- https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f
- https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc
- https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa
- https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3
- https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb
- https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937
- https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.