cbcvebase.
CVE-2026-46260
published 2026-06-03

CVE-2026-46260: In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node(). syzbot reported out-of-bound read in…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node(). syzbot reported out-of-bound read in fib6_add_rt2node(). [0] When IPv6 route is created with RTA_NH_ID, struct fib6_info does not have the trailing struct fib6_nh. The cited commit started to check !iter->fib6_nh->fib_nh_gw_family to ensure that rt6_qualify_for_ecmp() will return false for iter. If iter->nh is not NULL, rt6_qualify_for_ecmp() returns false anyway. Let's check iter->nh before reading iter->fib6_nh and avoid OOB read. [0]: BUG: KASAN: slab-out-of-bounds in fib6_add_rt2node+0x349c/0x3500 net/ipv6/ip6_fib.c:1142 Read of size 1 at addr ffff8880384ba6de by task syz.0.18/5500 CPU: 0 UID: 0 PID: 5500 Comm: syz.0.18 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inline] print_report+0xba/0x230 mm/kasan/report.c:482 kasan_report+0x117/0x150 mm/kasan/report.c:595 fib6_add_rt2node+0x349c/0x3500 net/ipv6/ip6_fib.c:1142 fib6_add_rt2node_nh net/ipv6/ip6_fib.c:1363 [inline] fib6_add+0x910/0x18c0 net/ipv6/ip6_fib.c:1531 __ip6_ins_rt net/ipv6/route.c:1351 [inline] ip6_route_add+0xde/0x1b0 net/ipv6/route.c:3957 inet6_rtm_newroute+0x268/0x19e0 net/ipv6/route.c:5660 rtnetlink_rcv_msg+0x7d5/0xbe0 net/core/rtnetlink.c:6958 netlink_rcv_skb+0x232/0x4b0 net/netlink/af_netlink.c:2550 netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline] netlink_unicast+0x80f/0x9b0 net/netlink/af_netlink.c:1344 netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1894 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg net/socket.c:742 [inline] ____sys_sendmsg+0xa68/0xad0 net/socket.c:2592 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2646 __sys_sendmsg net/socket.c:2678 [inline] __do_sys_sendmsg net/socket.c:2683 [inline] __se_sys_sendmsg net/socket.c:2681 [inline] __

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 50b7c7a255858a85c4636a1e990ca04591153dca < bcc60ad129ae1837cf809c81bff56ec8bfdb6b11bcc60ad129ae1837cf809c81bff56ec8bfdb6b11
linuxlinux>= 6.12.70 < 6.12.756.12.75
linuxlinux>= 6.18.10 < 6.18.146.18.14
linuxlinux>= 6.6.124 < 6.6.1286.6.128
linuxlinux>= b8ad2d53f706aeea833d23d45c0758398fede580 < 03b5051e02f5a3772eee57493ad697d4b505b0c203b5051e02f5a3772eee57493ad697d4b505b0c2
linuxlinux>= bbf4a17ad9ffc4e3d7ec13d73ecd59dea149ed25 < 500e54615c97bc3c427e52305a6fcd38a0e008a3500e54615c97bc3c427e52305a6fcd38a0e008a3
linuxlinux>= bbf4a17ad9ffc4e3d7ec13d73ecd59dea149ed25 < 8244f959e2c125c849e569f5b23ed49804cce6958244f959e2c125c849e569f5b23ed49804cce695
linuxlinux>= d8143c54ceeba232dc8a13aa0afa14a44b371d93 < bf5009a06e03ee9a51052bb59f2228a5e4e66260bf5009a06e03ee9a51052bb59f2228a5e4e66260
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.12.70 < 6.12.756.12.75
linuxlinux_kernel>= 6.18.10 < 6.18.146.18.14
linuxlinux_kernel>= 6.19.1 < 6.19.46.19.4
linuxlinux_kernel>= 6.6.124 < 6.6.1286.6.128
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.