Executive brief
A vulnerability in the Linux kernel's IPv6 implementation could allow network traffic to corrupt system memory. The issue occurs when processing specific types of routing headers used in low-power and lossy networks (RPL). An attacker could potentially cause a system crash or interfere with network operations by sending specially crafted packets that trigger an internal calculation error.
Technical details
An integer overflow exists in the `ipv6_rpl_srh_decompress()` function within `net/ipv6/exthdrs.c`. The function calculates the output header length (`hdrlen`) using the formula `(((n + 1) * sizeof(struct in6_addr)) >> 3)`. Because `hdrlen` is an 8-bit unsigned integer (`__u8`), values of `n >= 127` result in a value exceeding 255, causing a silent truncation. This leads to an incorrect buffer offset in `ipv6_rpl_srh_rcv()`, causing the compressed header to overlap and corrupt the decompressed routing data. The fix tightens the validation bound for `n` from 255 to 127 to ensure the calculated length always fits within the 8-bit field.
Affected products
- Linux Linux Kernel 8610c7c6e3bd to 75b3680047bf, fd238c51b0fa, 3618b34942b7, 97e06791368c, de02fc049352, c0487a9c1e11, 6fe1cb312038, 9d5e7a46a9f6
Timeline
- 2026-05-25: disclosed: Initial patch submission by Rahul Chandelkar
- 2026-06-19: patched: Patch committed to stable branches by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE published in NVD dataset
References
- https://git.kernel.org/stable/c/3618b34942b76471d044369bfd30d58c39068bf1
- https://git.kernel.org/stable/c/6fe1cb312038516cb4d9fa089d700af7059f1a64
- https://git.kernel.org/stable/c/75b3680047bf09af8e7e471a7a6ddf2ce5847f56
- https://git.kernel.org/stable/c/97e06791368c01f0ad2a4b3269c2abe19485ca32
- https://git.kernel.org/stable/c/9d5e7a46a9f6d8f503b41bfefef70659845f1679
- https://git.kernel.org/stable/c/c0487a9c1e116cf349e2d1f302d9019670460858
- https://git.kernel.org/stable/c/de02fc049352af5a9595f015511222d0a85c326b