Junglewise Threat Intelligence

CVE-2026-46120: Linux Kernel use-after-free in ip6erspan_changelink

CVE-2026-46120 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 GRE (Generic Routing Encapsulation) implementation could allow a local user to cause a system crash. By manipulating network namespaces, an attacker can trigger a memory error that leads to a 'use-after-free' condition. This results in a kernel panic or 'BUG' state, effectively causing a denial of service on the affected host.

Technical details

A use-after-free vulnerability exists in net/ipv6/ip6_gre.c within the ip6erspan_changelink() function. The root cause is the failure to use the cached network namespace (t->net) when re-inserting a tunnel into the per-netns hash after an IFLA_NET_NS_FD migration. This results in a stale entry remaining in the original namespace's hash; when that namespace is destroyed, ip6gre_exit_rtnl_net() attempts to walk the stale entry, triggering a slab-use-after-free and a subsequent kernel BUG at net/core/dev.c. The vulnerability is reachable from an unprivileged user namespace. Patches have been merged into multiple stable branches of the Linux kernel.

Affected products

  • Linux Linux Kernel v5.15+

Timeline

  • 2026-04-30: patched: Initial patch authored by Maoyi Xie
  • 2026-05-28: disclosed: CVE published to NVD dataset

References