« Volver al listado

CVE-2026-80792

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix use-after-free in ip6_finish_output2()

ip6_finish_output2() caches a pointer to the IPv6 destination address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit path or other encapsulation operations within lwtunnel_xmit() can reallocate the skb head, freeing the memory that daddr points to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale daddr pointer to compute the nexthop and to look up or create the neighbour entry. This results in a use-after-free read, which can leak sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or crash the system.

Leer descripción completaMostrar menos

Fix this by re-fetching the IPv6 header and the destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop computation and neighbour lookup operate on valid memory.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80792",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4132c4ad00ddbf3a175ea0d2c775b662a32f4c85",
              "lessThan": "75e0a544ebe9af663ef53ca21e9e9185c51fb54a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "c95f01b78266828a57060d754fcbfc92123a98ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "d960881b9312e781a3429aabceb223ce6b7c882f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "087ee0d914aaae929f1660c9ca878e367655ba1a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "3c770ac4e6f07af7c7b40c474a3efc61ffed7862",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "3dc98e5fe82d069dd29b124ffbdb679331dfea43",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "99219c82804f266189388e8bf1cf5135d10d5515",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "73a187384a8c8b983c7fea046d716b6752a1e7a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2",
              "lessThan": "d0d48d999b0eee6bb176ef4e39d9be868fa80f7e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1598154fd28ffa4a55beae1970475fd6776554b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.233",
              "lessThan": "5.10.267",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.289",
              "lessThan": "5.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/ipv6/ip6_output.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.267",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.154",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.106",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.47",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv6/ip6_output.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:05.460",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix use-after-free in ip6_finish_output2()\n\nip6_finish_output2() caches a pointer to the IPv6 destination\naddress (daddr) before invoking lwtunnel_xmit().  The LWT-BPF\ntransmit path or other encapsulation operations within\nlwtunnel_xmit() can reallocate the skb head, freeing the memory\nthat daddr points to.  When lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, the function continues to use the stale\ndaddr pointer to compute the nexthop and to look up or create the\nneighbour entry.  This results in a use-after-free read, which can\nleak sensitive kernel data, pollute the neighbour table with\narbitrary values, misdirect traffic, or crash the system.\n\nFix this by re-fetching the IPv6 header and the destination\naddress pointer after lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop\ncomputation and neighbour lookup operate on valid memory."
    }
  ],
  "lastModified": "2026-09-04T16:18:05.460",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}