Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component that could lead to a system crash or unpredictable behavior. The issue occurs when the system processes outgoing IPv6 traffic, potentially accessing memory that has already been freed. This could impact the stability and availability of affected systems, including certain industrial controllers that utilize the Linux kernel.
Technical details
A use-after-free (UAF) vulnerability exists in the net/ipv6/ip6_output.c component of the Linux kernel. The root cause is the lack of proper RCU (Read-Copy-Update) locking in the ip6_xmit() function when accessing the destination device (dst_dev). An attacker could potentially trigger this race condition during network transmission, leading to a kernel panic or memory corruption. The fix involves implementing rcu_read_lock() and utilizing dst_dev_rcu() to ensure the network device object remains valid during the transmission process. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 4a6ce2b6f2ec to f0a54d00d2f3
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2025-08-28: patched: Initial fix authored by Eric Dumazet
- 2025-11-12: disclosed: CVE published
References
- https://git.kernel.org/stable/c/9085e56501d93af9f2d7bd16f7fcfacdde47b99c
- https://git.kernel.org/stable/c/bd0905e2122e3680968cd0741966983490bf2ed3
- https://git.kernel.org/stable/c/f0a54d00d2f36de40266f47c27989853e8588656
- https://git.kernel.org/stable/c/f69fec6287565fdeb61f65e700a1184352306943
- https://git.kernel.org/stable/c/f7f9e924f23684b4b23cd9f976cceab24a968e34
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html