All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80792: ipv6: fix use-after-free in ip6_finish_output2()
@ 2026-09-04 15:11 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:11 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix use-after-free in ip6_finish_output2()

ip6_finish_output2() caches a pointer to the IPv6 destination
address (daddr) before invoking lwtunnel_xmit().  The LWT-BPF
transmit path or other encapsulation operations within
lwtunnel_xmit() can reallocate the skb head, freeing the memory
that daddr points to.  When lwtunnel_xmit() returns
LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale
daddr pointer to compute the nexthop and to look up or create the
neighbour entry.  This results in a use-after-free read, which can
leak sensitive kernel data, pollute the neighbour table with
arbitrary values, misdirect traffic, or crash the system.

Fix this by re-fetching the IPv6 header and the destination
address pointer after lwtunnel_xmit() returns
LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop
computation and neighbour lookup operate on valid memory.

The Linux kernel CVE team has assigned CVE-2026-80792 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.10.233 with commit 4132c4ad00ddbf3a175ea0d2c775b662a32f4c85 and fixed in 5.10.267 with commit 75e0a544ebe9af663ef53ca21e9e9185c51fb54a
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 5.15.218 with commit c95f01b78266828a57060d754fcbfc92123a98ed
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.1.185 with commit d960881b9312e781a3429aabceb223ce6b7c882f
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.6.154 with commit 087ee0d914aaae929f1660c9ca878e367655ba1a
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.12.106 with commit 3c770ac4e6f07af7c7b40c474a3efc61ffed7862
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 6.18.47 with commit 3dc98e5fe82d069dd29b124ffbdb679331dfea43
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.1.11 with commit 99219c82804f266189388e8bf1cf5135d10d5515
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.2.1 with commit 73a187384a8c8b983c7fea046d716b6752a1e7a3
	Issue introduced in 5.15 with commit e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2 and fixed in 7.3-rc1 with commit d0d48d999b0eee6bb176ef4e39d9be868fa80f7e
	Issue introduced in 5.4.289 with commit 1598154fd28ffa4a55beae1970475fd6776554b6

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80792
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/ipv6/ip6_output.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a
	https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed
	https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f
	https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a
	https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862
	https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43
	https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515
	https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3
	https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 15:17 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:11 CVE-2026-80792: ipv6: fix use-after-free in ip6_finish_output2() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.