Executive brief
The Linux kernel's IPv6 routing subsystem contains a race condition in the nexthop replacement logic that allows an attacker to trigger use-after-free memory reads. This can crash the kernel or potentially lead to information disclosure when concurrent IPv6 route operations occur. Systems using IPv6 routing are affected.
Technical details
A race condition exists in net/ipv4/nexthop.c where fib6_check_nh_list() and __nexthop_replace_notify() walk the nh->f6i_list linked list without holding the nh->lock spinlock during nexthop replace operations. Concurrently, IPv6 RTM_NEWROUTE/RTM_DELROUTE messages execute without RTNL serialization and mutate the same list under nh->lock (fib6_add_rt2node_nh(), fib6_purge_rt()), freeing fib6_info structures that are still being read. This triggers KASAN slab-use-after-free errors. The fix adds spin_lock_bh()/spin_unlock_bh() protection around the list iterations. No user interaction is required; triggering requires crafted netlink messages from a privileged context or network-exposed routing daemon.
Affected products
- Linux Linux Multiple versions (see timeline)
Timeline
- 2026-08-15: disclosed: CVE published
- 2026-07-24: patched: Patch merged upstream (commit 072cd1f2)
- 2026-07-22: other: Fix submitted by Xiang Mei (Microsoft)