KernelScan.io

CRITICAL Introduced in 2.6.19

ipv6 HAO NetworkHeader Deref

CVE-2026-63922

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.

02

Engine v0.4.0

Risk summary

A remote, unauthenticated attacker can send a crafted IPv6 packet containing a Home Address Option (HAO) in a destination extension header to corrupt kernel heap memory, crash the receiving Linux kernel, or potentially achieve code execution. The bug is directly reachable from the network without privileges or user interaction.

Affectednet/ipv6/exthdrs.c (IPv6 extension headers / MIPv6 HAO)

Vulnerability analysis

ip6_parse_tlv() caches the network header pointer (nh = skb_network_header(skb)) before iterating over IPv6 TLV options. When the IPV6_TLV_HAO case is reached, ipv6_dest_hao() is called, which may invoke pskb_expand_head() on an skb. pskb_expand_head() can reallocate the skb head buffer and invalidate the previously cached nh pointer. After ipv6_dest_hao() returns, the loop continues using the stale nh pointer to parse any remaining TLVs or padding, resulting in reads and writes from/to freed or reused heap memory. The fix adds a single line to refresh nh from skb_network_header(skb) immediately after ipv6_dest_hao() returns, matching the existing pattern used elsewhere in the same function. The attack surface is purely network-facing: any system with IPv6 and MIPv6 (CONFIG_IPV6_MIP6) enabled can receive such a packet from an unauthenticated remote sender, triggering use of the stale pointer and memory corruption.

03

BranchIntroducedFixed inPatch commit
5.102.6.195.10.259b3ac54e5c905
5.152.6.195.15.210f8aabed3ff3e
6.12.6.196.1.1761a11eb7431e3
6.62.6.196.6.14312d957979e4a
6.122.6.196.12.93ff375ed1cba8
6.182.6.196.18.35751db1b802a0
7.02.6.197.0.129b6dcc0a39fd
mainline2.6.197.1f7b52afe3592