net: ipv6: clear suppressed fib6 rule result
Summary
| CVE | CVE-2026-74581 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-21 17:16:44 UTC |
| Updated | 2026-08-21 17:16:44 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6 rule result
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),
but leaves res->rt6 pointing at the released rt6_info.
If no later rule supplies a replacement, fib6_rule_lookup() still sees
res.rt6 and returns that stale dst to its caller. A suppressing rule can
therefore leak a released route back to rt6_lookup(), and the next put
hits rcuref_put_slowpath() from dst_release().
Clear res->rt6 when suppressing the route so suppressed lookups fall
through to the null dst instead of reusing the released one. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 209d35ee34e25f9668c404350a1c86d914c54ffa 90c57310e266eb94e4a80d6b15a9ca131d2e82cb git |
Not specified |
| CNA |
Linux |
Linux |
affected 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383 5d29b286c9de0b309e94b9ed083aa1a2f429434f git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 354db6243eca59e9d187ffbf8b7955b044ce84dc git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 6d98c70fe0ba8c7708bfd5b2a5174d2086775daa git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 9bad152c42b37499162367fe47867411e62fffa3 git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 dc3ab04220667f254f4348572b2a0b3febff89fb git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 a341c091ca0bfae377747b1b59a3bd8ebe18a937 git |
Not specified |
| CNA |
Linux |
Linux |
affected cdef485217d30382f3bf6448c54b4401648fe3f1 6aea62e433fe1b586202a5fee8b5807ce635e1d7 git |
Not specified |
| CNA |
Linux |
Linux |
affected ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29 git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.10.84 5.10.265 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.15.7 5.15.216 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.4.164 5.5 semver |
Not specified |
| CNA |
Linux |
Linux |
affected 5.16 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.16 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.265 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.216 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.183 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.151 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.