Executive brief
A vulnerability in the Linux kernel's IPv6 GRE (Generic Routing Encapsulation) implementation could allow a local user to cause a system crash. By manipulating network namespaces, an attacker can trigger a memory error that leads to a 'use-after-free' condition. This results in a kernel panic or 'BUG' state, effectively causing a denial of service on the affected host.
Technical details
A use-after-free vulnerability exists in net/ipv6/ip6_gre.c within the ip6erspan_changelink() function. The root cause is the failure to use the cached network namespace (t->net) when re-inserting a tunnel into the per-netns hash after an IFLA_NET_NS_FD migration. This results in a stale entry remaining in the original namespace's hash; when that namespace is destroyed, ip6gre_exit_rtnl_net() attempts to walk the stale entry, triggering a slab-use-after-free and a subsequent kernel BUG at net/core/dev.c. The vulnerability is reachable from an unprivileged user namespace. Patches have been merged into multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel v5.15+
Timeline
- 2026-04-30: patched: Initial patch authored by Maoyi Xie
- 2026-05-28: disclosed: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/1d324c2f43f70c965f25c58cc3611c779adbe47e
- https://git.kernel.org/stable/c/311fdd26eb4443d43b909cc67a10f3a5fd1b21b2
- https://git.kernel.org/stable/c/cf7fc624329e76c6394653d12353e1d033adea91
- https://git.kernel.org/stable/c/e70cfb40c3a99b232cd42c6a6a10f0d8e039dc82
- https://git.kernel.org/stable/c/eca62bb0569de4d43a4dac06a2092a9d4ca1d702