CVE-2026-68127
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
10/08/2026
Última modificación:
19/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ila: reload IPv6 header after pskb_may_pull in checksum adjust<br />
<br />
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling<br />
pskb_may_pull(). On a non-linear skb whose transport header sits in a page<br />
fragment, pskb_may_pull() can call __pskb_pull_tail() / pskb_expand_head()<br />
and free the old skb head, leaving ip6h dangling; the following<br />
get_csum_diff(ip6h, p) then reads freed memory. ila_update_ipv6_locator()<br />
uses ip6h (and the iaddr derived from it) again after the csum-adjust<br />
call and additionally writes the new locator through that pointer.<br />
<br />
Impact: a remote IPv6 packet routed through a configured ILA<br />
csum-adjust-transport route or receive-side mapping triggers a<br />
slab-use-after-free in ila_update_ipv6_locator() (KASAN). The route or<br />
mapping requires CAP_NET_ADMIN to configure, but trigger packets are<br />
unauthenticated once it exists.<br />
<br />
Reload ip6h after each pskb_may_pull() in ila_csum_adjust_transport()<br />
before the csum-diff read. In ila_update_ipv6_locator() only the<br />
ILA_CSUM_ADJUST_TRANSPORT case pulls the skb, so reload ip6h and iaddr in<br />
that case alone before the destination-address write; the neutral-map<br />
modes never pull and keep their cached pointers.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/1eadcb43893b897ade85ac5bf5c618054bc3c655
- https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d
- https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b
- https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1
- https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594
- https://git.kernel.org/stable/c/ba353caafb06ccee57b78d3254e3cebf1dea4a93
- https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc
- https://git.kernel.org/stable/c/e451a904606c571f731ef7a06b3398619dce5300


