All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-93226: ipv6: use RCU iterator to dump route exceptions
Date: Thu, 24 Sep 2026 17:28:42 +0200	[thread overview]
Message-ID: <2026092441-CVE-2026-93226-6981@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ipv6: use RCU iterator to dump route exceptions

rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over
RCU-protected exception lists. The caller holds rcu_read_lock(), but does
not hold rt6_exception_lock, so rt6_insert_exception() can concurrently
add an entry with hlist_add_head_rcu().

KCSAN reports this race (irrelevant details omitted):

  ==================================================================
  BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions

  write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:
    rt6_insert_exception+0x3bb/0x760
    __ip6_rt_update_pmtu+0x4fe/0x750
    ip6_sk_update_pmtu+0x19a/0x3b0
    udpv6_err+0x3ff/0x800
    icmpv6_notify+0x1e1/0x440
    icmpv6_rcv+0x8c0/0xab0
    ip6_protocol_deliver_rcu+0x616/0x840
    ip6_input_finish+0xb9/0x160
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:
    rt6_nh_dump_exceptions+0xb3/0x260
    rt6_dump_route+0x53e/0x5f0
    fib6_dump_node+0x6d/0xf0
    fib6_walk_continue+0x290/0x2d0
    fib6_dump_table+0x28d/0x360
    inet6_dump_fib+0x37d/0x620
    rtnl_dumpit+0x7b/0xd0
    netlink_dump+0x3ae/0x7e0
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  4 locks held by dumper/549:
    ...
    #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620
    #2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360
    #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0

  value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100

  Reported by Kernel Concurrency Sanitizer on:
  CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted
  7.2.0-rc7-virtme #38 PREEMPT(lazy)
  ...

Use hlist_for_each_entry_rcu() to safely iterate over the exception list.

The Linux kernel CVE team has assigned CVE-2026-93226 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 5.10.270 with commit dffbfb3117138e8e0e09d05f507bd36ca1f696e5
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 5.15.221 with commit 6bd3f94ed858f2d072627546b4cdf712b0f8ea88
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.1.188 with commit 9c6be625e1a7258e845d6193b3b6b084a00f8e9e
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.6.157 with commit 3665abc3d2ae8a78cb67f858e848481432ec75db
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.12.109 with commit eda56ee17713f9dd834b922f7dbfa2e25fa6358c
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.18.50 with commit a602cd128d17a793e12888edc8eda85821ede7e1
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 7.2.4 with commit f6b1b15848fd91fe122dac0d19d3d666e35075b6
	Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 7.3-rc1 with commit 47cdab0d51aaa9bd85f8e4904585bd5bd4df4488

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-93226
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	net/ipv6/route.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/dffbfb3117138e8e0e09d05f507bd36ca1f696e5
	https://git.kernel.org/stable/c/6bd3f94ed858f2d072627546b4cdf712b0f8ea88
	https://git.kernel.org/stable/c/9c6be625e1a7258e845d6193b3b6b084a00f8e9e
	https://git.kernel.org/stable/c/3665abc3d2ae8a78cb67f858e848481432ec75db
	https://git.kernel.org/stable/c/eda56ee17713f9dd834b922f7dbfa2e25fa6358c
	https://git.kernel.org/stable/c/a602cd128d17a793e12888edc8eda85821ede7e1
	https://git.kernel.org/stable/c/f6b1b15848fd91fe122dac0d19d3d666e35075b6
	https://git.kernel.org/stable/c/47cdab0d51aaa9bd85f8e4904585bd5bd4df4488

                 reply	other threads:[~2026-09-24 15:31 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026092441-CVE-2026-93226-6981@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.