CRITICAL Introduced in 2.6.12
ipv6 JumboHop StalePointer
CVE-2026-63924
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI9.8CRITICAL
01Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. Let's recompute nh pointer to make sure any change won't mess things up.
02KernelScan AI Analysis
Risk summary
A remote, unauthenticated attacker can send a crafted IPv6 packet with a Jumbo Payload hop-by-hop option to corrupt memory in the receiving Linux kernel. The bug exists because the network header pointer is not refreshed after pskb_trim_rcsum() potentially reallocates the socket buffer, leaving a stale pointer that subsequent code may dereference. This can lead to information disclosure, arbitrary memory corruption, or kernel crash. The vulnerability has been present since Linux 2.6.12 and is reachable from any network path where IPv6 is enabled.
Vulnerability analysis
The vulnerability is a stale pointer in ip6_parse_tlv() in net/ipv6/exthdrs.c. While processing IPv6 hop-by-hop extension headers, the function calls ipv6_hop_jumbo() to handle the IPV6_TLV_JUMBO option. Inside that helper, pskb_trim_rcsum() may reallocate or modify the socket buffer's data pointers. After ipv6_hop_jumbo() returns, the local 'nh' pointer (obtained earlier via skb_network_header()) may reference freed or relocated memory. Any subsequent use of 'nh' constitutes a use-after-free / memory-corruption primitive against attacker-reachable heap objects (the old skb buffer). The fix refreshes 'nh' by calling skb_network_header(skb) immediately after ipv6_hop_jumbo() returns. The attack surface is fully network-reachable: an unauthenticated remote attacker can send a specially crafted IPv6 packet with a Jumbo Payload option to trigger this path on any system with IPv6 enabled.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 5.10 | 2.6.12 | 5.10.259 | b3ac54e5c905 |
| 5.15 | 2.6.12 | 5.15.210 | 645b99b1a185 |
| 6.1 | 2.6.12 | 6.1.176 | 9e883eaa878f |
| 6.12 | 2.6.12 | 6.12.93 | 72af7beae774 |
| 7.0 | 2.6.12 | 7.0.12 | 2b56bbd928c0 |
| 6.6 | 2.6.12 | 6.6.143 | bddaa4dfc7f3 |
| 6.18 | 2.6.12 | 6.18.35 | c512e1c819df |
| mainline | 2.6.12 | 7.1 | d47548a36639 |