Executive brief
The Linux kernel's MPLS (Multiprotocol Label Switching) module contains a use-after-free vulnerability in the multipath routing logic. When processing certain network packets, a stale pointer to freed memory is dereferenced, allowing an attacker to potentially trigger a kernel crash or execute arbitrary code. This affects systems using MPLS routing with multiple paths and can be triggered by specially crafted network packets.
Technical details
The vulnerability is a use-after-free in the mpls_multipath_hash() function within net/mpls/af_mpls.c. The root cause is that the code caches a pointer to an MPLS header (hdr) while walking the label stack. After finding the bottom-of-stack label, it calls pskb_may_pull() to ensure sufficient data is available. If the inner IP header resides in nonlinear skb data with insufficient linear buffer tailroom, pskb_may_pull() invokes pskb_expand_head(), which reallocates the skb head and frees the old one. This leaves hdr pointing to the freed memory. When the code subsequently dereferences hdr to access the inner IPv4 or IPv6 header, it triggers a use-after-free. The fix reloads hdr from the reallocated skb head after each successful pskb_may_pull() call. The vulnerability requires network reachability and a specially crafted packet; no authentication or user interaction is required.
Affected products
- Linux Linux kernel Affected versions range from linux-2.6.11 through at least linux-6.19; exact versions not fully enumerated in advisory
Timeline
- 2026-09-11: disclosed
- 2026-08-18: patched: Commit 29e63b8d9fc150cc191b1c6eb7e16e1247e1b650 (mainline) and 49d38c1b4390412f8950d33dfaee0ccbd17beb81 (stable)