CVE-2026-89564

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ip: orphan prefetched skbs before multicast forwarding<br /> <br /> IPv4 and IPv6 input preserve an skb-&gt;sk association installed by<br /> bpf_sk_assign() so that local delivery can use the selected socket under<br /> RCU. Both address families can also prefetch a socket in UDP early demux.<br /> In both paths (BPF and UDP early demux) a reference is not guaranteed to<br /> be held on the socket.<br /> <br /> When a multicast packet is not locally deliverable, IPv6 hands the<br /> original skb to ip6_mr_input(). IPv4&amp;#39;s ip_mr_input() similarly keeps the<br /> original skb when local delivery is not needed. Either path can put the<br /> skb on an unresolved multicast route queue or forward it after the<br /> receive-side RCU section ends.<br /> <br /> After the prefetched socket is destroyed, a later skb free invokes<br /> sock_pfree() and dereferences the stale skb-&gt;sk. Orphan the skb before<br /> each non-local multicast forwarding path. Local delivery retains the<br /> original skb; the existing skb_clone() calls provide multicast forwarding<br /> with a socket-free clone.