KernelScan.io

CRITICAL

mpls MultipathHash UAF

CVE-2026-89555

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop when an MPLS route has multiple nexthops. While walking the MPLS label stack, the hash routine caches hdr for the current label. After finding the bottom-of-stack label, it calls pskb_may_pull() before reading the inner IP header. If an skb is constructed with the inner IP header in nonlinear data and insufficient tailroom in the linear head, pskb_may_pull() calls pskb_expand_head() to replace the skb head and free the old one. This leaves hdr pointing to freed memory. The IPv6 path can invalidate hdr again when it performs a second pull for the larger header. The issue was found through static analysis. A reproducer sending a legal Geneve packet through a bareudp/MPLS multipath setup triggered the same KASAN report in 2 of 2 unpatched runs: BUG: KASAN: slab-use-after-free in mpls_select_multipath Read of size 1 at addr ffff88800ecc6e20 by task ksoftirqd/1/23 Call Trace: mpls_select_multipath mpls_forward __netif_receive_skb_list_core netif_receive_skb_list_internal napi_complete_done gro_cell_poll __napi_poll net_rx_action Freed by task 23: kfree pskb_expand_head __pskb_pull_tail mpls_select_multipath Reload hdr from the current skb head after each successful pull before deriving the inner IPv4 or IPv6 header pointer.

02

Engine v0.6.0

Risk summary

A remote attacker can trigger a use-after-free in the MPLS multipath hash routine by sending a crafted packet with the inner IP header in nonlinear skb data through an MPLS multipath route. This can lead to kernel memory corruption, potentially allowing code execution or denial of service.

Affectednet/mpls/af_mpls.c (MPLS multipath forwarding)

Vulnerability analysis

When the MPLS multipath hash routine processes a packet whose inner IP header resides in nonlinear memory, it may reallocate the packet's header buffer to pull data into the linear region. A cached pointer to the old header location is left dangling after this reallocation, and subsequent reads through that pointer access freed memory. The fix ensures the header pointer is reloaded from the current packet buffer after each successful data pull before reading the inner IPv4 or IPv6 header. The vulnerable path is reached when forwarding packets over an MPLS route with multiple nexthops; an attacker can trigger it by sending a suitably constructed packet to a host performing MPLS forwarding, requiring no privileges.

03

BranchIntroducedFixed inPatch commit
7.2—7.2.429e63b8d9fc1
mainline—7.3-rc1—
6.18—6.18.5049d38c1b4390
4.94.9.84.10aa4fe0b450a4
5.10—5.10.270b1c0783b2fac
5.15—5.15.221bfaaff992383
6.12—6.12.109d82b90a38c2c
6.1—6.1.188d9640239827d
6.6—6.6.157fed638a24811