CVE-2026-89564
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
21/09/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ip: orphan prefetched skbs before multicast forwarding<br />
<br />
IPv4 and IPv6 input preserve an skb->sk association installed by<br />
bpf_sk_assign() so that local delivery can use the selected socket under<br />
RCU. Both address families can also prefetch a socket in UDP early demux.<br />
In both paths (BPF and UDP early demux) a reference is not guaranteed to<br />
be held on the socket.<br />
<br />
When a multicast packet is not locally deliverable, IPv6 hands the<br />
original skb to ip6_mr_input(). IPv4&#39;s ip_mr_input() similarly keeps the<br />
original skb when local delivery is not needed. Either path can put the<br />
skb on an unresolved multicast route queue or forward it after the<br />
receive-side RCU section ends.<br />
<br />
After the prefetched socket is destroyed, a later skb free invokes<br />
sock_pfree() and dereferences the stale skb->sk. Orphan the skb before<br />
each non-local multicast forwarding path. Local delivery retains the<br />
original skb; the existing skb_clone() calls provide multicast forwarding<br />
with a socket-free clone.
Impacto
Puntuación base 3.x
7.80
Gravedad 3.x
ALTA


