Junglewise Threat Intelligence

CVE-2026-74562: Linux kernel nexthop use-after-free in IPv6 route handling

CVE-2026-74562 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux. Vendors: Linux.

Executive brief

The Linux kernel's IPv6 routing subsystem contains a race condition in the nexthop replacement logic that allows an attacker to trigger use-after-free memory reads. This can crash the kernel or potentially lead to information disclosure when concurrent IPv6 route operations occur. Systems using IPv6 routing are affected.

Technical details

A race condition exists in net/ipv4/nexthop.c where fib6_check_nh_list() and __nexthop_replace_notify() walk the nh->f6i_list linked list without holding the nh->lock spinlock during nexthop replace operations. Concurrently, IPv6 RTM_NEWROUTE/RTM_DELROUTE messages execute without RTNL serialization and mutate the same list under nh->lock (fib6_add_rt2node_nh(), fib6_purge_rt()), freeing fib6_info structures that are still being read. This triggers KASAN slab-use-after-free errors. The fix adds spin_lock_bh()/spin_unlock_bh() protection around the list iterations. No user interaction is required; triggering requires crafted netlink messages from a privileged context or network-exposed routing daemon.

Affected products

  • Linux Linux Multiple versions (see timeline)

Timeline

  • 2026-08-15: disclosed: CVE published
  • 2026-07-24: patched: Patch merged upstream (commit 072cd1f2)
  • 2026-07-22: other: Fix submitted by Xiang Mei (Microsoft)

References