-
CVE-2026-97597
- EPSS 0.21%
- Veröffentlicht 25.09.2026 10:22:12
- Zuletzt bearbeitet 03.10.2026 11:18:06
- Erkennungen
ipv6: flowlabel: cap duplicate leases per socket
In the Linux kernel, the following vulnerability has been resolved: ipv6: flowlabel: cap duplicate leases per socket ipv6_flowlabel_get() allocates an ipv6_fl_socklist entry for every successful GET. The recheck path for a compatible existing flowlabel links another lease without applying any lease admission check. Repeated GET requests for one shareable label can therefore grow a socket's lease list without bound. Reject a new unprivileged lease once the socket already holds FL_MAX_PER_SOCK leases. Check this on the shared recheck path so reuse of a globally interned label, including the fl_intern() collision path, is covered as well. New-label admission remains under the existing mem_check() policy. Use capable(CAP_NET_ADMIN) rather than ns_capable(), matching mem_check(). An unprivileged user must not bypass the cap by creating a user namespace and a netns where they have CAP_NET_ADMIN, which would still consume host memory. Check the capability only when the socket reaches the limit, so successful unprivileged GET requests below the cap do not generate a capability audit. Do the admission check before updating linger and expires so a rejected GET does not refresh the shared label, matching the existing socket-list allocation failure path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
6d917992c22b6029fc2dc1bd464b7f6709357161
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
2f1a6dd5c80ceb902f50449efe899f29cd7918e3
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
467467bf4209f9f8add0c648bae763f92a0224c3
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
8d6cd188508513503805c156165de38e4e4a8615
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
6.12.*
Version
6.12.112
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.101 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/2f1a6dd5c80ceb902f50449efe899f29cd7918e3
https://git.kernel.org/stable/c/467467bf4209f9f8add0c648bae763f92a0224c3
https://git.kernel.org/stable/c/8d6cd188508513503805c156165de38e4e4a8615
https://git.kernel.org/stable/c/6d917992c22b6029fc2dc1bd464b7f6709357161