Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component that could lead to a system crash or unauthorized memory access. The issue occurs when the system attempts to log a warning message about a network address after that address has already been deleted from memory. This could allow a local attacker with limited privileges to compromise the stability of the system or potentially gain higher-level access.
Technical details
A use-after-free (UaF) vulnerability exists in the Linux kernel's IPv6 implementation within the 'addrconf_permanent_addr' helper function in 'net/ipv6/addrconf.c'. The root cause is a race condition where a diagnostic warning message (net_info_ratelimited) is triggered after the IPv6 address object (ifp) has been deleted via 'ipv6_del_addr'. An attacker with local access could exploit this by triggering specific IPv6 address configuration failures, leading to a kernel panic or potential arbitrary code execution. The fix involves reordering the statements to ensure the warning message is processed before the address object is deleted and moving the warning outside of the 'idev->lock' to avoid unnecessary contention.
Affected products
- Linux Linux kernel All versions prior to the fixed stable releases in April 2026
Timeline
- 2026-03-27: other: Vulnerability fixed in source code by Paolo Abeni
- 2026-05-08: disclosed: CVE-2026-43339 published
- 2026-05-08: advisory
References
- https://git.kernel.org/stable/c/25357b670afb5b517096da783abaa5cc4bf8359e
- https://git.kernel.org/stable/c/2d88ed7fa000e19c2dc0fa31b3a849e3f5bca5c1
- https://git.kernel.org/stable/c/3cd4efb5df72843dfac892d0b3c7a4a8bd926b65
- https://git.kernel.org/stable/c/7bfafa1b0cd582983ebec6bb20f0a435528fe567
- https://git.kernel.org/stable/c/7d9f2f4aabd116ca68fbdab5d8fb8dac74c2ea1e
- https://git.kernel.org/stable/c/bacc7f31085c9820922f00bc7d79756ffa13123a
- https://git.kernel.org/stable/c/eec49a33611f20336b357b3953df44f1a02049e8