CRITICAL Introduced in 4.4
ipv6 ICMPv6Rcv UAF
CVE-2026-53006
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI7.9HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker can send ICMPv6 packets to trigger a use-after-free in the kernel's ICMPv6 receive path (icmpv6_rcv()). Cached pointers to ipv6_hdr(skb)->saddr and daddr are stored before pskb_pull(), which may reallocate skb->head. When the stale pointers are later dereferenced in net_dbg_ratelimited(), they may reference freed heap memory. This can leak up to 32 bytes of kernel heap data to the kernel log (C:Low) and can cause a kernel panic or oops in softirq context (A:High). Systems with IPv6 enabled and exposed to any IP network are affected.
Vulnerability analysis
The root cause is that icmpv6_rcv() caches pointers to IPv6 source and destination addresses before functions that may reallocate the SKB head (pskb_pull() via skb_checksum_validate() or other processing). After reallocation, the cached pointers point to freed memory. The fix removes the cached variables and dereferences the addresses inline at the point of use. The bug is reachable from the network by any host that can send IPv6 packets to the target; no authentication or local access is required. The impact is read-only via the debug logging path, but dereferencing stale kernel pointers in interrupt context can crash the kernel.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.15 | 4.4 | 5.15.209 | aff0f28f5be8 |
| 6.1 | 4.4 | 6.1.175 | 38bdbc897c0d |
| 6.6 | 4.4 | 6.6.141 | 0069813e6ca9 |
| 7.0 | 4.4 | 7.0.10 | 085e31a811ef |
| mainline | 4.4 | 7.1 | f996edd7615e |
| 6.12 | 4.4 | 6.12.91 | 1e1f0f89ee46 |
| 5.10 | 4.4 | 5.10.258 | 7bff2c8fe5c3 |
| 6.18 | 4.4 | 6.18.33 | 7c66b368c6ff |