Impact
The flaw resides in the IPv6 multicast routing subsystem of the Linux kernel. When a multicast packet arrives on a link that lacks a valid Multicast Forwarding Cache (MFC) entry, the packet is queued in an unresolved state while its destination cache (dst) entry is freed. Subsequent resolution of the MFC with an incorrect parent interface triggers a report routine that clones the now‑freed dst reference, leading to a slab use‑after‑free. The resulting memory corruption can crash the kernel or allow an attacker to execute arbitrary code. The weakness aligns with CWE‑416: Use‑After‑Free.
Affected Systems
Any Linux deployment running a kernel version that contains the legacy ip6mr_cache_report routine and that forwards IPv6 multicast traffic is vulnerable. Specific version information is not provided in the advisory, so all kernels older than the applied patch are considered affected. Systems that enable the ip6_multicast forwarding feature and expose themselves to external IPv6 multicast traffic are at greatest risk.
Risk and Exploitability
The CVSS score of 7.8 flags a high‑severity condition, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing the perceived threat level. Exploitation requires an attacker who can inject crafted IPv6 multicast packets onto the network path that traverses the vulnerable host. An attacker who successfully triggers the use‑after‑free could cause a kernel panic, forcing a reboot (Denial of Service), or possibly execute arbitrary code if memory is overwritten with malicious data.
OpenCVE Enrichment