-

CVE-2026-97597

ipv6: flowlabel: cap duplicate leases per socket

In the Linux kernel, the following vulnerability has been resolved:

ipv6: flowlabel: cap duplicate leases per socket

ipv6_flowlabel_get() allocates an ipv6_fl_socklist entry for every
successful GET. The recheck path for a compatible existing flowlabel
links another lease without applying any lease admission check. Repeated
GET requests for one shareable label can therefore grow a socket's lease
list without bound.

Reject a new unprivileged lease once the socket already holds
FL_MAX_PER_SOCK leases. Check this on the shared recheck path so reuse
of a globally interned label, including the fl_intern() collision path,
is covered as well. New-label admission remains under the existing
mem_check() policy.

Use capable(CAP_NET_ADMIN) rather than ns_capable(), matching
mem_check(). An unprivileged user must not bypass the cap by creating a
user namespace and a netns where they have CAP_NET_ADMIN, which would
still consume host memory.

Check the capability only when the socket reaches the limit, so
successful unprivileged GET requests below the cap do not generate a
capability audit. Do the admission check before updating linger and
expires so a rejected GET does not refresh the shared label, matching
the existing socket-list allocation failure path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 6d917992c22b6029fc2dc1bd464b7f6709357161
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 2f1a6dd5c80ceb902f50449efe899f29cd7918e3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 467467bf4209f9f8add0c648bae763f92a0224c3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 8d6cd188508513503805c156165de38e4e4a8615
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2f1a6dd5c80ceb902f50449efe899f29cd7918e3
https://git.kernel.org/stable/c/467467bf4209f9f8add0c648bae763f92a0224c3
https://git.kernel.org/stable/c/8d6cd188508513503805c156165de38e4e4a8615
https://git.kernel.org/stable/c/6d917992c22b6029fc2dc1bd464b7f6709357161