Description
In the Linux kernel, the following vulnerability has been resolved:

ip6mr: do not clone dst in ip6mr_cache_report()

IPv6 input attaches a non-refcounted (NOREF) dst to skbs under RCU.
When an ingress multicast packet misses MFC lookup,
ip6mr_cache_unresolved() places the skb onto the unresolved queue,
escaping the receive-side RCU grace period.

If the underlying route is deleted and freed, and the MFC queue is later
resolved with a wrong parent interface, ip6_mr_forward() invokes
ip6mr_cache_report(..., MRT6MSG_WRONGMIF), which executes
dst_clone(skb_dst(pkt)) on the freed dst entry, triggering a slab
use-after-free.

Report packets queued to mroute6_sk (a raw socket) and netlink
notifications do not require an attached dst entry.

Fix this by:
1. Removing dst_clone() in ip6mr_cache_report() and ensuring report skbs
do not hold a dst.
2. Dropping skb_dst before queuing unresolved skbs in
ip6mr_cache_unresolved(), matching the fact that multicast
forwarding resolves outgoing routes anew via ip6_route_output().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free potentially causing kernel panic and arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the IPv6 multicast routing subsystem of the Linux kernel. When a multicast packet arrives on a link that lacks a valid Multicast Forwarding Cache (MFC) entry, the packet is queued in an unresolved state while its destination cache (dst) entry is freed. Subsequent resolution of the MFC with an incorrect parent interface triggers a report routine that clones the now‑freed dst reference, leading to a slab use‑after‑free. The resulting memory corruption can crash the kernel or allow an attacker to execute arbitrary code. The weakness aligns with CWE‑416: Use‑After‑Free.

Affected Systems

Any Linux deployment running a kernel version that contains the legacy ip6mr_cache_report routine and that forwards IPv6 multicast traffic is vulnerable. Specific version information is not provided in the advisory, so all kernels older than the applied patch are considered affected. Systems that enable the ip6_multicast forwarding feature and expose themselves to external IPv6 multicast traffic are at greatest risk.

Risk and Exploitability

The CVSS score of 7.8 flags a high‑severity condition, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing the perceived threat level. Exploitation requires an attacker who can inject crafted IPv6 multicast packets onto the network path that traverses the vulnerable host. An attacker who successfully triggers the use‑after‑free could cause a kernel panic, forcing a reboot (Denial of Service), or possibly execute arbitrary code if memory is overwritten with malicious data.

Generated by OpenCVE AI on September 20, 2026 at 02:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch removing dst_clone() in ip6mr_cache_report() and correcting the unresolved skb handling.
  • If an immediate kernel update is not possible, block or disable IPv6 multicast forwarding on the affected host to prevent the triggering of the vulnerable code paths.
  • After applying the fix or enforcing the network restriction, monitor system logs for kernel panics or abnormal crashes that might indicate lingering memory corruption; trigger an incident response if such events occur.

Generated by OpenCVE AI on September 20, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ip6mr: do not clone dst in ip6mr_cache_report() IPv6 input attaches a non-refcounted (NOREF) dst to skbs under RCU. When an ingress multicast packet misses MFC lookup, ip6mr_cache_unresolved() places the skb onto the unresolved queue, escaping the receive-side RCU grace period. If the underlying route is deleted and freed, and the MFC queue is later resolved with a wrong parent interface, ip6_mr_forward() invokes ip6mr_cache_report(..., MRT6MSG_WRONGMIF), which executes dst_clone(skb_dst(pkt)) on the freed dst entry, triggering a slab use-after-free. Report packets queued to mroute6_sk (a raw socket) and netlink notifications do not require an attached dst entry. Fix this by: 1. Removing dst_clone() in ip6mr_cache_report() and ensuring report skbs do not hold a dst. 2. Dropping skb_dst before queuing unresolved skbs in ip6mr_cache_unresolved(), matching the fact that multicast forwarding resolves outgoing routes anew via ip6_route_output().
Title ip6mr: do not clone dst in ip6mr_cache_report()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:06.232Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.130

Modified: 2026-09-18T18:17:42.500

Link: CVE-2026-90111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses