9.8
CVE-2026-74581
- EPSS 0.17%
- Veröffentlicht 21.08.2026 17:16:44
- Zuletzt bearbeitet 25.08.2026 06:18:31
- CVE-Watchlists
- Unerledigt
net: ipv6: clear suppressed fib6 rule result
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a replacement, fib6_rule_lookup() still sees res.rt6 and returns that stale dst to its caller. A suppressing rule can therefore leak a released route back to rt6_lookup(), and the next put hits rcuref_put_slowpath() from dst_release(). Clear res->rt6 when suppressing the route so suppressed lookups fall through to the null dst instead of reusing the released one.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
209d35ee34e25f9668c404350a1c86d914c54ffa
Version <
90c57310e266eb94e4a80d6b15a9ca131d2e82cb
Status
affected
Version
8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383
Version <
5d29b286c9de0b309e94b9ed083aa1a2f429434f
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
354db6243eca59e9d187ffbf8b7955b044ce84dc
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
6d98c70fe0ba8c7708bfd5b2a5174d2086775daa
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
9bad152c42b37499162367fe47867411e62fffa3
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
dc3ab04220667f254f4348572b2a0b3febff89fb
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
a341c091ca0bfae377747b1b59a3bd8ebe18a937
Status
affected
Version
cdef485217d30382f3bf6448c54b4401648fe3f1
Version <
6aea62e433fe1b586202a5fee8b5807ce635e1d7
Status
affected
Version
ee38eb8cf9a7323884c2b8e0adbbeb2192d31e29
Status
affected
Version
5.10.84
Version <
5.10.265
Status
affected
Version
5.15.7
Version <
5.15.216
Status
affected
Version
5.4.164
Version <
5.5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.16
Status
affected
Version
0
Version <
5.16
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.151
Status
unaffected
Version <=
6.12.*
Version
6.12.103
Status
unaffected
Version <=
6.18.*
Version
6.18.44
Status
unaffected
Version <=
7.1.*
Version
7.1.8
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/354db6243eca59e9d187ffbf8b7955b044ce84dc
https://git.kernel.org/stable/c/5d29b286c9de0b309e94b9ed083aa1a2f429434f
https://git.kernel.org/stable/c/6aea62e433fe1b586202a5fee8b5807ce635e1d7
https://git.kernel.org/stable/c/6d98c70fe0ba8c7708bfd5b2a5174d2086775daa
https://git.kernel.org/stable/c/90c57310e266eb94e4a80d6b15a9ca131d2e82cb
https://git.kernel.org/stable/c/9bad152c42b37499162367fe47867411e62fffa3
https://git.kernel.org/stable/c/a341c091ca0bfae377747b1b59a3bd8ebe18a937
https://git.kernel.org/stable/c/dc3ab04220667f254f4348572b2a0b3febff89fb