Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74581

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
21/08/2026
Última modificación:
21/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: ipv6: clear suppressed fib6 rule result<br /> <br /> fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),<br /> but leaves res-&gt;rt6 pointing at the released rt6_info.<br /> <br /> If no later rule supplies a replacement, fib6_rule_lookup() still sees<br /> res.rt6 and returns that stale dst to its caller. A suppressing rule can<br /> therefore leak a released route back to rt6_lookup(), and the next put<br /> hits rcuref_put_slowpath() from dst_release().<br /> <br /> Clear res-&gt;rt6 when suppressing the route so suppressed lookups fall<br /> through to the null dst instead of reusing the released one.

Impacto