KernelScan.io

CRITICAL Introduced in 4.4

ipv6 ICMPv6Rcv UAF

CVE-2026-53006

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.9HIGH

01

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull() is problematic since skb->head can change. Remove these temporary variables: - We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr when net_dbg_ratelimited() is called in the slow path. - Avoid potential future misuse after pskb_pull() call.

02

Engine v0.3.0

Risk summary

A remote, unauthenticated attacker can send ICMPv6 packets to trigger a use-after-free in the kernel's ICMPv6 receive path (icmpv6_rcv()). Cached pointers to ipv6_hdr(skb)->saddr and daddr are stored before pskb_pull(), which may reallocate skb->head. When the stale pointers are later dereferenced in net_dbg_ratelimited(), they may reference freed heap memory. This can leak up to 32 bytes of kernel heap data to the kernel log (C:Low) and can cause a kernel panic or oops in softirq context (A:High). Systems with IPv6 enabled and exposed to any IP network are affected.

Affectednet/ipv6/icmp.c (IPv6 ICMPv6 receive path)

Vulnerability analysis

The root cause is that icmpv6_rcv() caches pointers to IPv6 source and destination addresses before functions that may reallocate the SKB head (pskb_pull() via skb_checksum_validate() or other processing). After reallocation, the cached pointers point to freed memory. The fix removes the cached variables and dereferences the addresses inline at the point of use. The bug is reachable from the network by any host that can send IPv6 packets to the target; no authentication or local access is required. The impact is read-only via the debug logging path, but dereferencing stale kernel pointers in interrupt context can crash the kernel.

03

BranchIntroducedFixed inPatch commit
5.154.45.15.209aff0f28f5be8
6.14.46.1.17538bdbc897c0d
6.64.46.6.1410069813e6ca9
7.04.47.0.10085e31a811ef
mainline4.47.1f996edd7615e
6.124.46.12.911e1f0f89ee46
5.104.45.10.2587bff2c8fe5c3
6.184.46.18.337c66b368c6ff