Executive brief
A use-after-free vulnerability exists in the Linux kernel's IPv4 routing code that handles network path MTU (maximum transmission unit) updates. An attacker with local or network access could exploit this race condition to cause a kernel panic or potentially execute code with kernel privileges, disrupting network services or compromising system security.
Technical details
The vulnerability is a use-after-free in the fib_nhc_update_mtu() function, which walks the nexthop exception table under RTNL (route netlink) lock but without proper synchronization against PMTU exception updates. The function uses rcu_dereference_protected() with an unconditional true condition while missing fnhe_lock, allowing a race where CPU 0 reads a pointer to a nexthop exception entry while CPU 1 simultaneously removes and frees that entry via update_or_create_fnhe(). After a grace period, CPU 0 dereferences the freed memory. The fix serializes PMTU field updates by acquiring fnhe_lock during the walk while using RCU to keep entries alive during short critical sections, avoiding long global lock contention.
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2026-08-22: disclosed