Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system attempts to read network flow information while that information is simultaneously being deleted. This can lead to a system instability or a complete crash, potentially disrupting operations or services running on the affected machine.
Technical details
A use-after-free vulnerability exists in net/ipv6/ip6_flowlabel.c due to a race condition between flowlabel release and RCU-protected readers. The function fl_release() prematurely frees 'fl->opt' for exclusive flowlabels when the user count drops to zero, even though the parent 'struct ip6_flowlabel' remains visible in the global hash table until garbage collection. A concurrent reader of /proc/net/ip6_flowlabel (via ip6fl_seq_show) can dereference this freed memory, resulting in a kernel oops or crash. The fix defers the freeing of the option block until the final RCU teardown in fl_free_rcu(). This affects various Linux kernel versions and downstream products like Siemens SIMATIC S7-1500 CPUs.
Affected products
- Linux Linux Kernel Fixed in 6.14, 6.13, 6.12, 6.11, 6.6, 6.1, 5.15, 5.10, 5.4, 4.19
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-04-25: disclosed
- 2026-04-18: patched: Patched in various stable kernel branches
References
- https://git.kernel.org/stable/c/3c54b66c83fb8fcbde8e6a7bf90b65856e39f827
- https://git.kernel.org/stable/c/414726b69921fe6355ae453f5b35e68dd078342a
- https://git.kernel.org/stable/c/4b6798024f7b2d535f3db1002c760143cdbd1bd3
- https://git.kernel.org/stable/c/572ce62778519a7d4d1c15f55dd2e45a474133c4
- https://git.kernel.org/stable/c/5a6b15f861b7c1304949e3350d23490a5fe429fd
- https://git.kernel.org/stable/c/6c7fbdb8ffde6413640de7cfbd7c976c353e89f8
- https://git.kernel.org/stable/c/8027964931785cb73d520ac70a342a3dc16c249b