KernelScan.io

CRITICAL Introduced in 6.9

ipv6 IOAM HdrPointer UAF

CVE-2026-64132

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to point into the skb's linear data buffer. Later, the code calls skb_ensure_writable(), which might reallocate the buffer: if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) goto drop; /* Trace pointer may have changed */ trace = (struct ioam6_trace_hdr *)(skb_network_header(skb) + optoff + sizeof(*hdr)); ioam6_fill_trace_data(skb, ns, trace, true); ioam6_event(IOAM6_EVENT_TRACE, dev_net(skb->dev), GFP_ATOMIC, (void *)trace, hdr->opt_len - 2); If the skb is cloned or lacks sufficient linear headroom, skb_ensure_writable() will invoke pskb_expand_head(), which reallocates the skb's data buffer and frees the old one, invalidating pointers to it. While the code recalculates the trace pointer immediately after the call to skb_ensure_writable(), it fails to recalculate the hdr pointer. This patch fixes the above by recalculating the hdr pointer before passing hdr->opt_len to ioam6_event(), so that we avoid any UaF.

02

Engine v0.4.0

Risk summary

A remote attacker can send a crafted IPv6 packet with an IOAM hop-by-hop option that triggers a use-after-free in the kernel's IPv6 extension header processing path. When skb_ensure_writable() reallocates the socket buffer, the stale hdr pointer is dereferenced to read opt_len from freed heap memory. Per industry convention for attacker-reachable heap corruption, this UAF primitive is treated as presumptively exploitable for information disclosure, integrity compromise, and denial of service.

Affectednet/ipv6/exthdrs.c (IPv6 IOAM extension header processing)

Vulnerability analysis

The vulnerability is a use-after-free in ipv6_hop_ioam() in net/ipv6/exthdrs.c. The hdr pointer is initialized to point into the skb's linear data buffer before skb_ensure_writable() is called. If the skb is cloned or lacks sufficient headroom, skb_ensure_writable() calls pskb_expand_head(), which reallocates the data buffer and frees the old one. The code correctly recalculates the trace pointer after this call, but fails to recalculate the hdr pointer. The stale hdr pointer is then dereferenced to read hdr->opt_len when calling ioam6_event(), constituting a use-after-free read on freed heap memory. The fix recalculates both hdr and trace pointers from skb_network_header() after skb_ensure_writable() returns, ensuring both pointers are valid. The attack surface is network-reachable: any IPv6 packet with an IOAM hop-by-hop option processed by a node acting as an IOAM transit or sink node can trigger this path without authentication.

03

BranchIntroducedFixed inPatch commit
6.126.96.12.92769723124b7c
6.186.96.18.3424de676da63c
7.06.97.0.115af905aa8e91
mainline6.97.1e46e6bc97fb1