From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-93226: ipv6: use RCU iterator to dump route exceptions
Date: Thu, 24 Sep 2026 17:28:42 +0200 [thread overview]
Message-ID: <2026092441-CVE-2026-93226-6981@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ipv6: use RCU iterator to dump route exceptions
rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over
RCU-protected exception lists. The caller holds rcu_read_lock(), but does
not hold rt6_exception_lock, so rt6_insert_exception() can concurrently
add an entry with hlist_add_head_rcu().
KCSAN reports this race (irrelevant details omitted):
==================================================================
BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions
write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:
rt6_insert_exception+0x3bb/0x760
__ip6_rt_update_pmtu+0x4fe/0x750
ip6_sk_update_pmtu+0x19a/0x3b0
udpv6_err+0x3ff/0x800
icmpv6_notify+0x1e1/0x440
icmpv6_rcv+0x8c0/0xab0
ip6_protocol_deliver_rcu+0x616/0x840
ip6_input_finish+0xb9/0x160
...
entry_SYSCALL_64_after_hwframe+0x77/0x7f
read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:
rt6_nh_dump_exceptions+0xb3/0x260
rt6_dump_route+0x53e/0x5f0
fib6_dump_node+0x6d/0xf0
fib6_walk_continue+0x290/0x2d0
fib6_dump_table+0x28d/0x360
inet6_dump_fib+0x37d/0x620
rtnl_dumpit+0x7b/0xd0
netlink_dump+0x3ae/0x7e0
...
entry_SYSCALL_64_after_hwframe+0x77/0x7f
4 locks held by dumper/549:
...
#1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620
#2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360
#3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0
value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100
Reported by Kernel Concurrency Sanitizer on:
CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted
7.2.0-rc7-virtme #38 PREEMPT(lazy)
...
Use hlist_for_each_entry_rcu() to safely iterate over the exception list.
The Linux kernel CVE team has assigned CVE-2026-93226 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 5.10.270 with commit dffbfb3117138e8e0e09d05f507bd36ca1f696e5
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 5.15.221 with commit 6bd3f94ed858f2d072627546b4cdf712b0f8ea88
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.1.188 with commit 9c6be625e1a7258e845d6193b3b6b084a00f8e9e
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.6.157 with commit 3665abc3d2ae8a78cb67f858e848481432ec75db
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.12.109 with commit eda56ee17713f9dd834b922f7dbfa2e25fa6358c
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 6.18.50 with commit a602cd128d17a793e12888edc8eda85821ede7e1
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 7.2.4 with commit f6b1b15848fd91fe122dac0d19d3d666e35075b6
Issue introduced in 5.3 with commit 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9 and fixed in 7.3-rc1 with commit 47cdab0d51aaa9bd85f8e4904585bd5bd4df4488
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-93226
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/ipv6/route.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/dffbfb3117138e8e0e09d05f507bd36ca1f696e5
https://git.kernel.org/stable/c/6bd3f94ed858f2d072627546b4cdf712b0f8ea88
https://git.kernel.org/stable/c/9c6be625e1a7258e845d6193b3b6b084a00f8e9e
https://git.kernel.org/stable/c/3665abc3d2ae8a78cb67f858e848481432ec75db
https://git.kernel.org/stable/c/eda56ee17713f9dd834b922f7dbfa2e25fa6358c
https://git.kernel.org/stable/c/a602cd128d17a793e12888edc8eda85821ede7e1
https://git.kernel.org/stable/c/f6b1b15848fd91fe122dac0d19d3d666e35075b6
https://git.kernel.org/stable/c/47cdab0d51aaa9bd85f8e4904585bd5bd4df4488
reply other threads:[~2026-09-24 15:31 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026092441-CVE-2026-93226-6981@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.