Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system hang or crash. The issue occurs when the system processes specific IPv6 routing information, leading to an infinite loop that stalls the processor. This can result in a denial-of-service condition, impacting the availability of the affected system.
Technical details
A race condition exists in the Linux kernel's IPv6 routing subsystem within the rt6_fill_node() function. When writers holding the tb6_lock delete route siblings (list_del_rcu) without waiting for RCU readers, the RCU walker may continue pointing to an old ring structure. This prevents the softirq-side walker from reaching the end of the list, causing an infinite loop and subsequent CPU stall (soft lockup). The fix involves implementing an inside-loop check for the fib6_nsiblings value as a detach signal to safely break the loop. Patches have been released for multiple stable kernel branches including 6.1, 6.6, and 6.12.
Affected products
- Linux Linux Kernel 6.1.128 to 6.1.176, 6.6.75 to 6.6.143, 6.12.2 to 6.12.93, 6.11.11 to 6.12, 6.13
Timeline
- 2026-05-27: patched: Initial patch submitted by Jiayuan Chen
- 2026-07-19: advisory: CVE-2026-63969 published
References
- https://git.kernel.org/stable/c/279853aec9f58d5cd723e6e5617c1c3337b30383
- https://git.kernel.org/stable/c/5e40de719ee76b8d96e2556ce36dbd3bd07bf37d
- https://git.kernel.org/stable/c/9f72412bcf60144f252b0d6205106abf14344abc
- https://git.kernel.org/stable/c/b014a63d2f2c2c767762b548381882dfb1655529
- https://git.kernel.org/stable/c/c65b1f60237daac7c56c2652e064cc566a45dc81
- https://git.kernel.org/stable/c/dc36a04621dcc2447dae428709207810b6c06e14