KernelScan.io

CRITICAL Introduced in 2.6.12

ipv6 JumboHop StalePointer

CVE-2026-63924

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. Let's recompute nh pointer to make sure any change won't mess things up.

02

Engine v0.4.0

Risk summary

A remote, unauthenticated attacker can send a crafted IPv6 packet with a Jumbo Payload hop-by-hop option to corrupt memory in the receiving Linux kernel. The bug exists because the network header pointer is not refreshed after pskb_trim_rcsum() potentially reallocates the socket buffer, leaving a stale pointer that subsequent code may dereference. This can lead to information disclosure, arbitrary memory corruption, or kernel crash. The vulnerability has been present since Linux 2.6.12 and is reachable from any network path where IPv6 is enabled.

Affectednet/ipv6/exthdrs.c (IPv6 extension header parsing)

Vulnerability analysis

The vulnerability is a stale pointer in ip6_parse_tlv() in net/ipv6/exthdrs.c. While processing IPv6 hop-by-hop extension headers, the function calls ipv6_hop_jumbo() to handle the IPV6_TLV_JUMBO option. Inside that helper, pskb_trim_rcsum() may reallocate or modify the socket buffer's data pointers. After ipv6_hop_jumbo() returns, the local 'nh' pointer (obtained earlier via skb_network_header()) may reference freed or relocated memory. Any subsequent use of 'nh' constitutes a use-after-free / memory-corruption primitive against attacker-reachable heap objects (the old skb buffer). The fix refreshes 'nh' by calling skb_network_header(skb) immediately after ipv6_hop_jumbo() returns. The attack surface is fully network-reachable: an unauthenticated remote attacker can send a specially crafted IPv6 packet with a Jumbo Payload option to trigger this path on any system with IPv6 enabled.

03

BranchIntroducedFixed inPatch commit
5.102.6.125.10.259b3ac54e5c905
5.152.6.125.15.210645b99b1a185
6.12.6.126.1.1769e883eaa878f
6.122.6.126.12.9372af7beae774
7.02.6.127.0.122b56bbd928c0
6.62.6.126.6.143bddaa4dfc7f3
6.182.6.126.18.35c512e1c819df
mainline2.6.127.1d47548a36639