CVE-2026-53275

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
25/06/2026
Last modified:
08/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipv6: mcast: Fix use-after-free when processing MLD queries<br /> <br /> When processing an MLD query, a pointer to the multicast group address<br /> is retrieved when initially parsing the packet. This pointer is later<br /> dereferenced without being reloaded despite the fact that the skb header<br /> might have been reallocated following the pskb_may_pull() calls, leading<br /> to a use-after-free [1].<br /> <br /> Fix by copying the multicast group address when the packet is initially<br /> parsed.<br /> <br /> [1]<br /> BUG: KASAN: slab-use-after-free in __mld_query_work (net/ipv6/mcast.c:1512)<br /> Read of size 8 at addr ffff8881154b8e90 by task kworker/4:1/118<br /> <br /> Workqueue: mld mld_query_work<br /> Call Trace:<br /> <br /> dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)<br /> print_address_description.constprop.0 (mm/kasan/report.c:378)<br /> print_report (mm/kasan/report.c:482)<br /> kasan_report (mm/kasan/report.c:595)<br /> __mld_query_work (net/ipv6/mcast.c:1512)<br /> mld_query_work (net/ipv6/mcast.c:1563)<br /> process_one_work (kernel/workqueue.c:3314)<br /> worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)<br /> kthread (kernel/kthread.c:436)<br /> ret_from_fork (arch/x86/kernel/process.c:158)<br /> ret_from_fork_asm (arch/x86/entry/entry_64.S:245)<br /> <br /> <br /> [...]<br /> <br /> Freed by task 118:<br /> kasan_save_stack (mm/kasan/common.c:57)<br /> kasan_save_track (mm/kasan/common.c:78)<br /> kasan_save_free_info (mm/kasan/generic.c:584)<br /> __kasan_slab_free (mm/kasan/common.c:253 mm/kasan/common.c:285)<br /> kfree (./include/linux/kasan.h:235 mm/slub.c:2689 mm/slub.c:6251 mm/slub.c:6566)<br /> pskb_expand_head (net/core/skbuff.c:2335)<br /> __pskb_pull_tail (net/core/skbuff.c:2878 (discriminator 4))<br /> __mld_query_work (net/ipv6/mcast.c:1495 (discriminator 1))<br /> mld_query_work (net/ipv6/mcast.c:1563)<br /> process_one_work (kernel/workqueue.c:3314)<br /> worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)<br /> kthread (kernel/kthread.c:436)<br /> ret_from_fork (arch/x86/kernel/process.c:158)<br /> ret_from_fork_asm (arch/x86/entry/entry_64.S:245)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.15 (including) 5.15.210 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 6.1.176 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (including) 6.6.143 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.94 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.18.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (including) 7.0.13 (excluding)
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*