-

CVE-2026-93226

ipv6: use RCU iterator to dump route exceptions

In the Linux kernel, the following vulnerability has been resolved:

ipv6: use RCU iterator to dump route exceptions

rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over
RCU-protected exception lists. The caller holds rcu_read_lock(), but does
not hold rt6_exception_lock, so rt6_insert_exception() can concurrently
add an entry with hlist_add_head_rcu().

KCSAN reports this race (irrelevant details omitted):

  ==================================================================
  BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions

  write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:
    rt6_insert_exception+0x3bb/0x760
    __ip6_rt_update_pmtu+0x4fe/0x750
    ip6_sk_update_pmtu+0x19a/0x3b0
    udpv6_err+0x3ff/0x800
    icmpv6_notify+0x1e1/0x440
    icmpv6_rcv+0x8c0/0xab0
    ip6_protocol_deliver_rcu+0x616/0x840
    ip6_input_finish+0xb9/0x160
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:
    rt6_nh_dump_exceptions+0xb3/0x260
    rt6_dump_route+0x53e/0x5f0
    fib6_dump_node+0x6d/0xf0
    fib6_walk_continue+0x290/0x2d0
    fib6_dump_table+0x28d/0x360
    inet6_dump_fib+0x37d/0x620
    rtnl_dumpit+0x7b/0xd0
    netlink_dump+0x3ae/0x7e0
    ...
    entry_SYSCALL_64_after_hwframe+0x77/0x7f

  4 locks held by dumper/549:
    ...
    #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620
    #2: (&tb->tb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360
    #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0

  value changed: 0xffff8a7c44e05700 -> 0xffff8a7c45d60100

  Reported by Kernel Concurrency Sanitizer on:
  CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted
  7.2.0-rc7-virtme #38 PREEMPT(lazy)
  ...

Use hlist_for_each_entry_rcu() to safely iterate over the exception list.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < dffbfb3117138e8e0e09d05f507bd36ca1f696e5
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < 6bd3f94ed858f2d072627546b4cdf712b0f8ea88
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < 9c6be625e1a7258e845d6193b3b6b084a00f8e9e
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < 3665abc3d2ae8a78cb67f858e848481432ec75db
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < eda56ee17713f9dd834b922f7dbfa2e25fa6358c
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < a602cd128d17a793e12888edc8eda85821ede7e1
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < f6b1b15848fd91fe122dac0d19d3d666e35075b6
Status affected
Version 1e47b4837f3bdaa425727cfe09f5ae3b6c4c41a9
Version < 47cdab0d51aaa9bd85f8e4904585bd5bd4df4488
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/dffbfb3117138e8e0e09d05f507bd36ca1f696e5
https://git.kernel.org/stable/c/6bd3f94ed858f2d072627546b4cdf712b0f8ea88
https://git.kernel.org/stable/c/9c6be625e1a7258e845d6193b3b6b084a00f8e9e
https://git.kernel.org/stable/c/3665abc3d2ae8a78cb67f858e848481432ec75db
https://git.kernel.org/stable/c/eda56ee17713f9dd834b922f7dbfa2e25fa6358c
https://git.kernel.org/stable/c/a602cd128d17a793e12888edc8eda85821ede7e1
https://git.kernel.org/stable/c/f6b1b15848fd91fe122dac0d19d3d666e35075b6
https://git.kernel.org/stable/c/47cdab0d51aaa9bd85f8e4904585bd5bd4df4488