KernelScan.io

HIGH Public exploit Introduced in 2.6.12

DirtyAH6

CVE-2026-80844

CVSS 7.8 / 10.0 KernelScan AI

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

01

In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described by the routing header's hdrlen field. That assumption does not hold for raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one address, but can carry an arbitrary segments_left value. With segments_left equal to 255, the function moves its address pointer 4,064 bytes backwards and passes a 4,064-byte length to memmove(), resulting in an out-of-bounds access. Validate the invariant locally before modifying the routing header or performing any address-pointer arithmetic, and propagate malformed-header errors to the existing AH6 input and output error paths.

02

Engine v0.6.0

Risk summary

A malformed IPv6 routing header with an oversized segments_left field causes an out-of-bounds memory access in the AH6 authentication handler. Local users with raw socket access can trigger this to corrupt kernel memory, potentially leading to privilege escalation or denial of service. The vulnerability is reachable on any system with IPv6 and AH support enabled.

Affectednet/ipv6/ah6.c (xfrm AH6)

Vulnerability analysis

The IPv6 authentication header processing code assumes that a routing header's segment count matches its actual length, but this is not enforced for raw packets generated locally. A crafted local packet can claim far more segments than exist, causing the kernel to access memory well outside the header buffer during address rearrangement. The fix checks that the segment count is valid before performing any address calculations or data movement, rejecting malformed headers. A local user with access to raw IPv6 sockets can trigger the bug; on default configurations this requires no special privileges because unprivileged users can acquire the necessary capability through user namespaces.

Exploit availability

KernelScan found public exploit code for this CVE. Open it in the CVE browser to see what we found, where, and how strong the evidence is — that needs a free account with a confirmed email address.

03

BranchIntroducedFixed inPatch commit
5.102.6.125.10.2692dc650956e4e
5.152.6.125.15.22048b0e36cf543
6.12.6.126.1.1871b7e066eabcc
6.122.6.126.12.1081516e31ac458
6.182.6.126.18.496733ae71268a
7.12.6.127.1.130bf11081ad37
7.22.6.127.2.346640c814f25
mainline2.6.127.3-rc17bad4bda74dc
6.62.6.126.6.156f00df8500e5a