From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F29D14EC67E for ; Fri, 4 Sep 2026 15:17:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535046; cv=none; b=pKnx4TUIqUGSPVDRKBB1tMlpVHx2LUxWR0VaFrYxzLb/pADHgtiIJsPeypY5b/u6TE3x859JwVPm0mDpegJ5vOSDlSsk5CQlF/oq/fEoCITcy6gqxyKRGOT80Z/bm6GV+fkTRSMrOV14TxCyVJU1LJLwcImEfqi6N777rqatwpI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788535046; c=relaxed/simple; bh=6NrXi7bdKit2n82fusp8vSc/wiJKbtmnoitllkWtKzs=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Y9NY+oQcs7630Cxa7woOA7OCR3BDkt/vBC1b91PtZ+G/0nzg67pAIPQukmRS/3KINmFF0dEG6vrHyhJZ97wL9RsbxlHDK8Juq3Z76lZvGII/Fox0j8HnQ5OAvY+bX223a7jtdXhnG+cnhafnCqvld1hWSdUHXGqLs9GG1QEb/2A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=yWgMW65E; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="yWgMW65E" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 288031F00A3D; Fri, 4 Sep 2026 15:17:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788535044; bh=yZUsq7dFIbTpb/O/hJVo8L0l6GXah8H4UIsi3Y5E+yE=; h=From:To:Cc:Subject:Date:Reply-To; b=yWgMW65EproOehjm5Dp1jq9F2k9m9R7Z6mAP/JowY9g4kWuoL00cYeKPtcMccKHBy uWq809eiFllzNQcyzePRXZYMa2B8MJ0UTvyABhIEH5A7XYLzPuxg+wTgpmcaSs7mgf d5DWVCad5qpQZP3DVeybbPWcC9gtC//L5Uku2OAg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80792: ipv6: fix use-after-free in ip6_finish_output2() Date: Fri, 4 Sep 2026 17:11:31 +0200 Message-ID: <2026090407-CVE-2026-80792-668e@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4297; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=W3Ia95iNS+84we2B9BgyiuilADoIks7a64E2RIAzB1M=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7ncrxT0UV5GT8Apjkd/E/dI7Ze1LjgOpa6Ot7ua8y p+38ilTRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEwkzIdhweW1l+JW7Bd2eyH+ 17va9oJVVtmqNwwLLny+4Xoq4dSMqiPBL2JeJ30+eYSZBwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ipv6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system. Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory. The Linux kernel CVE team has assigned CVE-2026-80792 to this issue. Affected and fixed versions =========================== Issue introduced in 5.10.233 with commit 4132c4ad00ddbf3a175ea0d2c775b662a32f4c85 and fixed in 5.10.267 with commit 75e0a544ebe9af663ef53ca21e9e9185c51fb54a Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 5.15.218 with commit c95f01b78266828a57060d754fcbfc92123a98ed Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.1.185 with commit d960881b9312e781a3429aabceb223ce6b7c882f Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.6.154 with commit 087ee0d914aaae929f1660c9ca878e367655ba1a Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.12.106 with commit 3c770ac4e6f07af7c7b40c474a3efc61ffed7862 Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.18.47 with commit 3dc98e5fe82d069dd29b124ffbdb679331dfea43 Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.1.11 with commit 99219c82804f266189388e8bf1cf5135d10d5515 Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.2.1 with commit 73a187384a8c8b983c7fea046d716b6752a1e7a3 Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.3-rc1 with commit d0d48d999b0eee6bb176ef4e39d9be868fa80f7e Issue introduced in 5.4.289 with commit 1598154fd28ffa4a55beae1970475fd6776554b6 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80792 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ipv6/ip6_output.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862 https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43 https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515 https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3 https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e