๐Ÿ” CVE Alert

CVE-2026-68127

UNKNOWN 0.0

ila: reload IPv6 header after pskb_may_pull in checksum adjust

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling pskb_may_pull(). On a non-linear skb whose transport header sits in a page fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head() and free the old skb head, leaving ip6h dangling; the following get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator() uses ip6h (and the iaddr derived from it) again after the csum-adjust call and additionally writes the new locator through that pointer. Impact: a remote IPv6 packet routed through a configured ILA csum-adjust-transport route or receive-side mapping triggers a slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or mapping requires CAP_NET_ADMIN to configure, but trigger packets are unauthenticated once it exists. Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport() before the csum-diff read. In ila_update_ipv6_locator() only the ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in that case alone before the destination-address write; the neutral-map modes never pull and keep their cached pointers.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
33f11d16142b06588eedfc1dd8cf93790979a712 < 896a9512d0d83c2a4b357e5585b7b62a8e3f95c1 33f11d16142b06588eedfc1dd8cf93790979a712 < 7097a0280b178237265681be66d1bef11d15894b 33f11d16142b06588eedfc1dd8cf93790979a712 < 472aba2603ca74c4f7722cb0c0296942b0776b8d 33f11d16142b06588eedfc1dd8cf93790979a712 < c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc 33f11d16142b06588eedfc1dd8cf93790979a712 < 92d3817649df2b0b6a008a686c8275c88d7ef594
Linux / Linux
4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1 git.kernel.org: https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b git.kernel.org: https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d git.kernel.org: https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc git.kernel.org: https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594