Executive brief
A vulnerability exists in the Linux kernel's networking component (Netfilter) that could allow an attacker to crash the system or potentially access sensitive information. The issue occurs when the system processes certain IPv6 network packets with invalid headers, which the firewall fails to properly reject. This could lead to service outages or unauthorized data access on affected Linux-based servers and devices.
Technical details
A vulnerability in the `eui64_mt6()` function within `net/ipv6/netfilter/ip6t_eui64.c` allows for an out-of-bounds read or invalid memory access. The root cause is an insufficient check that only rejected invalid MAC headers when the packet fragment offset was non-zero (`par->fragoff != 0`). For packets where the offset is zero, the code proceeds to call `eth_hdr(skb)` even if the MAC header is invalid or missing. A remote, unauthenticated attacker can exploit this over the network by sending malformed IPv6 packets. This can result in a kernel panic (Denial of Service) or potentially the disclosure of kernel memory. The issue has been patched in multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel from 2.6.12.1 up to 6.6.136, 6.7 up to 6.12.83, 6.13 up to 6.18.24, 6.19 up to 6.19.14, 7.0-rc1 up to 7.0-rc7
Timeline
- 2026-04-25: disclosed: Initial disclosure of the vulnerability.
- 2026-04-25: advisory: NVD published the CVE record.
- 2026-04-27: patched: Patches merged into various stable kernel branches.
References
- https://git.kernel.org/stable/c/288138418bef956f8b295751a4536c60f0e89f4a
- https://git.kernel.org/stable/c/309ae3e9a51a69699ca94eac5fac5688fa562d55
- https://git.kernel.org/stable/c/4d75bc2cd093bf5803edf512c099bfb220fd6459
- https://git.kernel.org/stable/c/7d6a57411caf54df025860c9b1a82cd42d57a562
- https://git.kernel.org/stable/c/807d6ee15804df6f01a35c910f09612e858739a6
- https://git.kernel.org/stable/c/9eda5478746ef7dc0e4e537b5a5e4b0ca1027091
- https://git.kernel.org/stable/c/d5603591373441fecf9951833d6d873e09320f08