SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64132

CRITICAL · CVSS 9.8 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's IPv6 implementation, specifically in the handling of the header pointer within the ioam6_event function. An attacker could exploit this flaw to cause a use-after-free condition, potentially leading to arbitrary code execution or system crashes. Organizations using Linux systems, particularly those relying on IPv6 networking, should prioritize patching this critical vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-64132
Severity
CRITICAL
CVSS
9.8
EPSS
0.49%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to point into the skb's linear data buffer. Later, the code calls skb_ensure_writable(), which might reallocate the buffer: if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) goto drop; /* Trace pointer may have changed */ trace = (struct ioam6_trace_hdr *)(skb_network_header(skb) + optoff + sizeof(*hdr)); ioam6_fill_trace_data(skb, ns, trace, true); ioam6_event(IOAM6_EVENT_TRACE, dev_net(skb->dev), GFP_ATOMIC, (void *)trace, hdr->opt_len - 2); If the skb is cloned or lacks sufficient linear headroom, skb_ensure_writable() will invoke pskb_expand_head(), which reallocates the skb's data buffer and frees the old one, invalidating pointers to it. While the code recalculates the trace pointer immediately after the call to skb_ensure_writable(), it fails to recalculate the hdr pointer. This patch fixes the above by recalculating the hdr pointer before passing hdr->opt_len to ioam6_event(), so that we avoid any UaF.

Related CVEs

Other vulnerabilities affecting the same vendor(s)