7.8
CVE-2026-89564
- EPSS 0.14%
- Veröffentlicht 11.09.2026 19:44:35
- Zuletzt bearbeitet 21.09.2026 14:17:23
- Erkennungen
ip: orphan prefetched skbs before multicast forwarding
In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forwarding IPv4 and IPv6 input preserve an skb->sk association installed by bpf_sk_assign() so that local delivery can use the selected socket under RCU. Both address families can also prefetch a socket in UDP early demux. In both paths (BPF and UDP early demux) a reference is not guaranteed to be held on the socket. When a multicast packet is not locally deliverable, IPv6 hands the original skb to ip6_mr_input(). IPv4's ip_mr_input() similarly keeps the original skb when local delivery is not needed. Either path can put the skb on an unresolved multicast route queue or forward it after the receive-side RCU section ends. After the prefetched socket is destroyed, a later skb free invokes sock_pfree() and dereferences the stale skb->sk. Orphan the skb before each non-local multicast forwarding path. Local delivery retains the original skb; the existing skb_clone() calls provide multicast forwarding with a socket-free clone.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
cf7fbe660f2dbd738ab58aea8e9b0ca6ad232449
Version <
e62aef7d6a5b27569bf540bbe11a9482117ff588
Status
affected
Version
cf7fbe660f2dbd738ab58aea8e9b0ca6ad232449
Version <
a8af6fbac895f057c4b8ff8a2e3fb4c5827fe4ce
Status
affected
Version
cf7fbe660f2dbd738ab58aea8e9b0ca6ad232449
Version <
f1281d4b99089fbaf0d3579bba62a814ebb4de4d
Status
affected
Version
cf7fbe660f2dbd738ab58aea8e9b0ca6ad232449
Version <
e36ce6e78fe3fc3c071a26750783b7ba081ce10d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.7
Status
affected
Version
0
Version <
5.7
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.034 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/a8af6fbac895f057c4b8ff8a2e3fb4c5827fe4ce
https://git.kernel.org/stable/c/f1281d4b99089fbaf0d3579bba62a814ebb4de4d
https://git.kernel.org/stable/c/e36ce6e78fe3fc3c071a26750783b7ba081ce10d
https://git.kernel.org/stable/c/e62aef7d6a5b27569bf540bbe11a9482117ff588