cbcvebase.
CVE-2026-46099
published 2026-05-27

CVE-2026-46099: In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input()…

PriorityP343high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.32%
24.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() unconditionally. On PREEMPT_RT, ksoftirqd is preemptible and a higher-priority task can release the underlying pcpu_rt between the lookup and the caching through a concurrent FIB lookup on a shared nexthop. Simplified race sequence: ksoftirqd/X higher-prio task (same CPU X) ----------- -------------------------------- seg6_input_core(,skb)/rpl_input(skb) dst_cache_get() -> miss ip6_route_input(skb) -> ip6_pol_route(,skb,flags) [RT6_LOOKUP_F_DST_NOREF in flags] -> FIB lookup resolves fib6_nh [nhid=N route] -> rt6_make_pcpu_route() [creates pcpu_rt, refcount=1] pcpu_rt->sernum = fib6_sernum [fib6_sernum=W] -> cmpxchg(fib6_nh.rt6i_pcpu, NULL, pcpu_rt) [slot was empty, store succeeds] -> skb_dst_set_noref(skb, dst) [dst is pcpu_rt, refcount still 1] rt_genid_bump_ipv6() -> bumps fib6_sernum [fib6_sernum from W to Z] ip6_route_output() -> ip6_pol_route() -> FIB lookup resolves fib6_nh [nhid=N] -> rt6_get_pcpu_route() pcpu_rt->sernum != fib6_sernum [W <> Z, stale] -> prev = xchg(rt6i_pcpu, NULL) -> dst_release(prev) [prev is pcpu_rt, refcount 1->0, dead] dst = skb_dst(skb) [dst is the dead pcpu_rt] dst_cache_set_ip6(dst) -> dst_hold() on dead dst -> WARN / use-after-free For the race to occur, ksoftirqd must be preemptible (PREEMPT_RT without PREEMPT_RT_NEEDS_BH_LOCK) and a concurrent task must be able to release the pcpu_rt. Shared nexthop objects provide such a path, as two routes pointing to the same nhid share the same fib6_nh and its rt6i_pcpu entry. Fix seg6_input_core() and rpl_input() by calling skb_dst_force() after ip6_route_input() to force the NOREF dst into a refcounted one before caching. The output path is not affected as ip6_route_output() already returns a refcounted dst.

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < 51fef5a7c4d160839199e941929456ba21ddf73c51fef5a7c4d160839199e941929456ba21ddf73c
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < b258b849a580285a1692e782ebc902b44c884a71b258b849a580285a1692e782ebc902b44c884a71
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < 6bd17925bd6866027a6555db17905b9fc073d38d6bd17925bd6866027a6555db17905b9fc073d38d
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < 52f9db67f8f35f436366cf4980b4f0a2583d0ef052f9db67f8f35f436366cf4980b4f0a2583d0ef0
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < b778b6d095421619c331fd2d7751143cd5387103b778b6d095421619c331fd2d7751143cd5387103
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < 9dd5481f960e337b81d7dfe429529495c1c481c09dd5481f960e337b81d7dfe429529495c1c481c0
linuxlinux>= af4a2209b1344939eaac11f269c261d347cbc3ee < f9c52a6ba9780bd27e0bf4c044fd91c13c778b6ef9c52a6ba9780bd27e0bf4c044fd91c13c778b6e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 4.12 < 5.15.2095.15.209
linuxlinux_kernel>= 5.16 < 6.1.1756.1.175
linuxlinux_kernel>= 6.13 < 6.18.276.18.27
linuxlinux_kernel>= 6.19 < 7.0.47.0.4
linuxlinux_kernel>= 6.2 < 6.6.1406.6.140
linuxlinux_kernel>= 6.7 < 6.12.866.12.86
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.