Junglewise Threat Intelligence

CVE-2026-68127: Linux kernel ILA use-after-free in checksum adjust

CVE-2026-68127 · Severity: critical · CVSS 9.8 · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Identifier Locator Addressing (ILA) module contains a use-after-free vulnerability in IPv6 packet processing. When an IPv6 packet is routed through a configured ILA checksum-adjust mapping, a memory corruption can occur that crashes the system or corrupts kernel memory. While the ILA configuration requires administrator privileges, the attack packets themselves are unauthenticated and can be sent by any remote attacker once the mapping is set up.

Technical details

The vulnerability is a use-after-free (CWE-416) in the ILA module's IPv6 packet handling. The root cause is that `ila_csum_adjust_transport()` caches a pointer to the IPv6 header before calling `pskb_may_pull()`. If the SKB (kernel socket buffer) is non-linear with the transport header in a page fragment, `pskb_may_pull()` can internally invoke `pskb_expand_head()`, which reallocates and frees the original SKB head, leaving the cached pointer dangling. Subsequent reads and writes through this stale pointer corrupt freed memory detected by KASAN. Attack preconditions include a prior CAP_NET_ADMIN configuration of an ILA route/mapping with csum-adjust mode; however, once configured, unauthenticated remote IPv6 packets trigger the vulnerability. The fix reloads the IPv6 header pointer after each `pskb_may_pull()` call before dereferencing it.

Affected products

  • Linux Linux kernel Versions prior to the fix (affecting multiple kernel series from 3.x through 7.x)

Timeline

  • 2026-08-10: disclosed: CVE-2026-68127 published
  • 2026-08-03: patched
  • 2026-07-14: other: Fix committed by Michael Bommarito

References

Related threats