« Volver al listado

CVE-2026-93226

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ipv6: use RCU iterator to dump route exceptions

rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over RCU-protected exception lists. The caller holds rcu_read_lock(), but does not hold rt6_exception_lock, so rt6_insert_exception() can concurrently add an entry with hlist_add_head_rcu().

KCSAN reports this race (irrelevant details omitted):

Use hlist_for_each_entry_rcu() to safely iterate over the exception list.

Detalles técnicos trazas, registros y código del informe original
  ==================================================================
  BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions

  write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:
    rt6_insert_exception+0x3bb/0x760
    __ip6_rt_update_pmtu+0x4fe/0x750
    ip6_sk_update_pmtu+0x19a/0x3b0
    udpv6_err+0x3ff/0x800
    icmpv6_notify+0x1e1/0x440
    icmpv6_rcv+0x8c0/0xab0
    ip6_protocol_deliver_rcu+0x616/0x840
    ip6_input_finish+0xb9/0x160
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:
    rt6_nh_dump_exceptions+0xb3/0x260
    rt6_dump_route+0x53e/0x5f0
    fib6_dump_node+0x6d/0xf0
    fib6_walk_continue+0x290/0x2d0
    fib6_dump_table+0x28d/0x360
    inet6_dump_fib+0x37d/0x620
    rtnl_dumpit+0x7b/0xd0
    netlink_dump+0x3ae/0x7e0
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  4 locks held by dumper/549:
    ...
    #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620
    #2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360
    #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0

  value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100

  Reported by Kernel Concurrency Sanitizer on:
  CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted
  7.2.0-rc7-virtme #38 PREEMPT(lazy)
  ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93226",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "dffbfb3117138e8e0e09d05f507bd36ca1f696e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "6bd3f94ed858f2d072627546b4cdf712b0f8ea88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "9c6be625e1a7258e845d6193b3b6b084a00f8e9e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "3665abc3d2ae8a78cb67f858e848481432ec75db",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "eda56ee17713f9dd834b922f7dbfa2e25fa6358c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "a602cd128d17a793e12888edc8eda85821ede7e1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "f6b1b15848fd91fe122dac0d19d3d666e35075b6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9",
              "lessThan": "47cdab0d51aaa9bd85f8e4904585bd5bd4df4488",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/ipv6/route.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/ipv6/route.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:17.973",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3665abc3d2ae8a78cb67f858e848481432ec75db",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/47cdab0d51aaa9bd85f8e4904585bd5bd4df4488",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6bd3f94ed858f2d072627546b4cdf712b0f8ea88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9c6be625e1a7258e845d6193b3b6b084a00f8e9e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a602cd128d17a793e12888edc8eda85821ede7e1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dffbfb3117138e8e0e09d05f507bd36ca1f696e5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eda56ee17713f9dd834b922f7dbfa2e25fa6358c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f6b1b15848fd91fe122dac0d19d3d666e35075b6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: use RCU iterator to dump route exceptions\n\nrt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over\nRCU-protected exception lists. The caller holds rcu_read_lock(), but does\nnot hold rt6_exception_lock, so rt6_insert_exception() can concurrently\nadd an entry with hlist_add_head_rcu().\n\nKCSAN reports this race (irrelevant details omitted):\n\n  ==================================================================\n  BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions\n\n  write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:\n    rt6_insert_exception+0x3bb/0x760\n    __ip6_rt_update_pmtu+0x4fe/0x750\n    ip6_sk_update_pmtu+0x19a/0x3b0\n    udpv6_err+0x3ff/0x800\n    icmpv6_notify+0x1e1/0x440\n    icmpv6_rcv+0x8c0/0xab0\n    ip6_protocol_deliver_rcu+0x616/0x840\n    ip6_input_finish+0xb9/0x160\n    ...\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:\n    rt6_nh_dump_exceptions+0xb3/0x260\n    rt6_dump_route+0x53e/0x5f0\n    fib6_dump_node+0x6d/0xf0\n    fib6_walk_continue+0x290/0x2d0\n    fib6_dump_table+0x28d/0x360\n    inet6_dump_fib+0x37d/0x620\n    rtnl_dumpit+0x7b/0xd0\n    netlink_dump+0x3ae/0x7e0\n    ...\n    entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  4 locks held by dumper/549:\n    ...\n    #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620\n    #2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360\n    #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0\n\n  value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100\n\n  Reported by Kernel Concurrency Sanitizer on:\n  CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted\n  7.2.0-rc7-virtme #38 PREEMPT(lazy)\n  ...\n\nUse hlist_for_each_entry_rcu() to safely iterate over the exception list."
    }
  ],
  "lastModified": "2026-09-24T16:17:17.973",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}