9.8

CVE-2026-53006

ipv6: fix possible UAF in icmpv6_rcv()

In the Linux kernel, the following vulnerability has been resolved:

ipv6: fix possible UAF in icmpv6_rcv()

Caching saddr and daddr before pskb_pull() is problematic
since skb->head can change.

Remove these temporary variables:

- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr
  when net_dbg_ratelimited() is called in the slow path.

- Avoid potential future misuse after pskb_pull() call.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 4.4 < 5.10.258
LinuxLinux Kernel Version >= 5.11 < 5.15.209
LinuxLinux Kernel Version >= 5.16 < 6.1.175
LinuxLinux Kernel Version >= 6.2 < 6.6.141
LinuxLinux Kernel Version >= 6.7 < 6.12.91
LinuxLinux Kernel Version >= 6.13 < 6.18.33
LinuxLinux Kernel Version >= 6.19 < 7.0.10
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux Version9.0
RedhatEnterprise Linux Version10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.322
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

CWE-825 Expired Pointer Dereference

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

https://git.kernel.org/stable/c/7bff2c8fe5c35ae58bf73104f53db3676e6e5d94
Patch
https://git.kernel.org/stable/c/aff0f28f5be803de2452ce702631c021fcd9ce8a
Patch
https://git.kernel.org/stable/c/38bdbc897c0d83a3e2b925a51b69420f1feba29a
Patch
https://git.kernel.org/stable/c/0069813e6ca9309eca78022bcb3aeb1e9ef90a12
Patch
https://git.kernel.org/stable/c/1e1f0f89ee4692a64be3f3707ff8ac1ae57b03e7
Patch
https://git.kernel.org/stable/c/7c66b368c6ff453f99cb39d84af93e908e51eef2
Patch
https://git.kernel.org/stable/c/085e31a811ef234ef8c3e219c4636dfebfe7e10f
Patch
https://git.kernel.org/stable/c/f996edd7615e686ada141b7f3395025729ff8ccb
Patch
https://bugzilla.redhat.com/show_bug.cgi?id=2492363
Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53006.json
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-53006
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:45192
https://access.redhat.com/errata/RHSA-2026:47017
https://access.redhat.com/errata/RHSA-2026:47010
https://access.redhat.com/errata/RHSA-2026:47011