Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component. This flaw could allow a local user to cause a system crash or potentially execute unauthorized actions by exploiting a memory management error during network multicast operations. This impacts the overall stability and security of systems running affected versions of the Linux operating system.
Technical details
The vulnerability is a use-after-free (UAF) in net/ipv6/mcast.c. In the mld_del_delrec() function, the reference to 'pmc->idev' was being released via in6_dev_put() before the call to ip6_mc_clear_src(pmc). Because ip6_mc_clear_src() still requires access to the idev pointer, this creates a race condition or use-after-free scenario. An attacker with local access could potentially exploit this to cause a kernel panic or achieve elevated privileges. The fix involves reordering the operations to ensure the reference is only released after its final use. Patches have been backported to several stable kernel branches including 5.15.y, 6.1.y, 6.6.y, and 6.12.y.
Affected products
- Linux Linux Kernel 5.13 to 5.15.190, 6.1.147, 6.6.100, 6.12.40, 6.15.8
Timeline
- 2025-07-14: patched: Initial fix authored by Yue Haibing
- 2025-08-16: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1b5b413094af8d88a31b5df3fd262f6baca53841
- https://git.kernel.org/stable/c/5f18e0130194550dff734e155029ae734378b5ea
- https://git.kernel.org/stable/c/6e4eec86fe5f6b3fdbc702d1d36ac2a6e7ec0806
- https://git.kernel.org/stable/c/728db00a14cacb37f36e9382ab5fad55caf890cc
- https://git.kernel.org/stable/c/7929d27c747eafe8fca3eecd74a334503ee4c839
- https://git.kernel.org/stable/c/ae3264a25a4635531264728859dbe9c659fad554
- https://git.kernel.org/stable/c/dcbc346f50a009d8b7f4e330f9f2e22d6442fa26