Executive brief
The Linux kernel's IPv6 multicast routing subsystem improperly manages memory references when handling multicast packets that don't match existing routing rules. An attacker with access to send specially-crafted IPv6 multicast traffic could trigger a use-after-free condition, causing kernel crashes or potential code execution and compromising system availability and security.
Technical details
This vulnerability is a use-after-free (CWE-416) in the IPv6 multicast routing code (ip6mr.c). The vulnerability occurs when IPv6 input attaches a non-refcounted (NOREF) destination entry to socket buffers under RCU. When an ingress multicast packet misses MFC lookup, it is queued in unresolved state, escaping the receive-side RCU grace period. If the underlying route is subsequently deleted and freed, and the MFC queue is later resolved with a wrong parent interface, the ip6_mr_forward() function invokes ip6mr_cache_report() which attempts to clone the freed destination entry via dst_clone(skb_dst(pkt)), triggering heap memory corruption. The attack requires network-level access to send IPv6 multicast packets, and no authentication is required. The fix removes the problematic dst_clone() call and ensures report skbs drop their destination references before queuing.
Affected products
- Linux Linux kernel multiple versions (see NVD/kernel.org stable branches)
Timeline
- 2026-09-17: disclosed: CVE-2026-90111 published on NVD
- 2026-08-20: patched: Patch committed by Jakub Kicinski (commit 235b42b5860189eb8c27c36435ad932cae65a734) and backported to stable branches