-

CVE-2026-97472

ipv6: addrconf: fix temp address generation after prefix deprecation

In the Linux kernel, the following vulnerability has been resolved:

ipv6: addrconf: fix temp address generation after prefix deprecation

When a router temporarily deprecates an IPv6 prefix (either by sending a
Router Advertisement with Preferred Lifetime = 0 or by letting the
lifetime expire) and later restores it, the kernel permanently loses its
ability to generate temporary privacy addresses (RFC 8981) for that
prefix.

This happens because the address worker attempts to generate a
replacement temporary address when the current one nears expiration. As
the base prefix is deprecated already, the generation fails after
marking the temporary address as already having spawned a replacement
(ifp->regen_count++).

When the router eventually restores the prefix, the temporary address
becomes active again. However, once it naturally expires, the address
worker sees this temporary address already tried to generate one and
skips the regeneration.

Fix the issue by resetting the regen_count check of the latest temp
address generated for the prefix updated by the incoming RA.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < b00f7c1da82a809156f785ed37536c2d2584927d
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < 6da8ba900b85e6478e211427630c67595fb707a4
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < 4f7d2a8dc364c4e55d0a1533451339008512933f
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < f601ec5c92b3260c742f27a5d2fd289e30ae798f
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < bff7b87dfa28a1502c18d0c6f1fadda5162fa854
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < 4df5597c65446135362f72880995e8920f058fa0
Status affected
Version 76f793e3a47139d340185cbc1a314740c09b13d3
Version < e20d8922aa8fe441d291364c96c2179a005b79ea
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.2
Status affected
Version 0
Version < 3.2
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bff7b87dfa28a1502c18d0c6f1fadda5162fa854
https://git.kernel.org/stable/c/4df5597c65446135362f72880995e8920f058fa0
https://git.kernel.org/stable/c/e20d8922aa8fe441d291364c96c2179a005b79ea
https://git.kernel.org/stable/c/4f7d2a8dc364c4e55d0a1533451339008512933f
https://git.kernel.org/stable/c/6da8ba900b85e6478e211427630c67595fb707a4
https://git.kernel.org/stable/c/b00f7c1da82a809156f785ed37536c2d2584927d
https://git.kernel.org/stable/c/f601ec5c92b3260c742f27a5d2fd289e30ae798f