cbcvebase.
CVE-2026-23200
published 2026-02-14

CVE-2026-23200: In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix ECMP sibling count mismatch when clearing RTF_ADDRCONF syzbot reported a kernel…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix ECMP sibling count mismatch when clearing RTF_ADDRCONF syzbot reported a kernel BUG in fib6_add_rt2node() when adding an IPv6 route. [0] Commit f72514b3c569 ("ipv6: clear RA flags when adding a static route") introduced logic to clear RTF_ADDRCONF from existing routes when a static route with the same nexthop is added. However, this causes a problem when the existing route has a gateway. When RTF_ADDRCONF is cleared from a route that has a gateway, that route becomes eligible for ECMP, i.e. rt6_qualify_for_ecmp() returns true. The issue is that this route was never added to the fib6_siblings list. This leads to a mismatch between the following counts: - The sibling count computed by iterating fib6_next chain, which includes the newly ECMP-eligible route - The actual siblings in fib6_siblings list, which does not include that route When a subsequent ECMP route is added, fib6_add_rt2node() hits BUG_ON(sibling->fib6_nsiblings != rt->fib6_nsiblings) because the counts don't match. Fix this by only clearing RTF_ADDRCONF when the existing route does not have a gateway. Routes without a gateway cannot qualify for ECMP anyway (rt6_qualify_for_ecmp() requires fib_nh_gw_family), so clearing RTF_ADDRCONF on them is safe and matches the original intent of the commit. [0]: kernel BUG at net/ipv6/ip6_fib.c:1217! Oops: invalid opcode: 0000 [#1] SMP KASAN PTI CPU: 0 UID: 0 PID: 6010 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 RIP: 0010:fib6_add_rt2node+0x3433/0x3470 net/ipv6/ip6_fib.c:1217 [...] Call Trace: fib6_add+0x8da/0x18a0 net/ipv6/ip6_fib.c:1532 __ip6_ins_rt net/ipv6/route.c:1351 [inline] ip6_route_add+0xde/0x1b0 net/ipv6/route.c:3946 ipv6_route_ioctl+0x35c/0x480 net/ipv6/route.c:4571 inet6_ioctl+0x219/0x280 net/ipv6/af_inet6.c:577 sock_do_ioctl+0xdc/0x300 net/socket.c:1245 sock_ioctl+0x57

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux>= 03f642caab84bbfd138e74f671bb436186ea7e82 < d8143c54ceeba232dc8a13aa0afa14a44b371d93d8143c54ceeba232dc8a13aa0afa14a44b371d93
linuxlinux>= 3e5b25da0b4109a3e063759735e6ec4236ea5a05 < b8ad2d53f706aeea833d23d45c0758398fede580b8ad2d53f706aeea833d23d45c0758398fede580
linuxlinux>= 6.12.63 < 6.12.706.12.70
linuxlinux>= 6.17.13 < 6.186.18
linuxlinux>= 6.18.2 < 6.18.106.18.10
linuxlinux>= 6.6.120 < 6.6.1246.6.124
linuxlinux>= cb2b0caa8ca93cbe39177516669bf699c74f7041 < 50b7c7a255858a85c4636a1e990ca04591153dca50b7c7a255858a85c4636a1e990ca04591153dca
linuxlinux>= f72514b3c5698e4b900b25345e09f9ed33123de6 < bbf4a17ad9ffc4e3d7ec13d73ecd59dea149ed25bbf4a17ad9ffc4e3d7ec13d73ecd59dea149ed25
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 6.12.63 < 6.12.706.12.70
linuxlinux_kernel>= 6.17.13 < 6.186.18
linuxlinux_kernel>= 6.18.2 < 6.18.106.18.10
linuxlinux_kernel>= 6.6.120 < 6.6.1246.6.124
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-fips

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.