Executive brief
The Linux kernel's IPv6 In-band OAM (IOAM) feature contains a type confusion vulnerability in how it handles route destination entries. An attacker could exploit this to cause invalid memory access, potentially leading to denial of service or kernel crash on systems using IPv6 with IOAM tunneling enabled.
Technical details
The vulnerability is a type confusion in the IOAM tunnel implementation (net/ipv6/ioam6_iptunnel.c). The code embeds a dummy dst_entry directly in struct ioam6_lwt, but passes it to dst_cache_set_ip6() which eventually calls rt6_get_cookie(). That function casts the dst_entry as if it were part of struct rt6_info and reads fields from the wrong object layout. When rt->sernum becomes zero (aliasing with ioam6_lwt::cache::reset_ts), rt6_get_cookie() accesses per-CPU values at an invalid pointer. The fix embeds a full struct rt6_info instead of just dst_entry. Exploitation requires the system to have IPv6 IOAM tunneling active, making this a local or adjacent network attack vector. A patch is available in upstream Linux kernel.
Affected products
- Linux Linux kernel All versions with IPv6 IOAM support (introduced in Linux 6.0+)
Timeline
- 2026-08-15: disclosed
- 2026-06-21: patched: Upstream fix committed; stable releases via Greg Kroah-Hartman dated 2026-07-24