SB20260812421 - Use-after-free in Linux kernel ipv6 ila
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68127)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to use-after-free in ila_update_ipv6_locator() and ila_csum_adjust_transport() when processing a crafted IPv6 packet routed through a configured ILA checksum-adjust-transport route or receive-side mapping. A remote attacker can send a specially crafted IPv6 packet to trigger a use-after-free.
Exploitation requires a configured ILA checksum-adjust-transport route or receive-side mapping.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/472aba2603ca74c4f7722cb0c0296942b0776b8d
- https://git.kernel.org/stable/c/7097a0280b178237265681be66d1bef11d15894b
- https://git.kernel.org/stable/c/896a9512d0d83c2a4b357e5585b7b62a8e3f95c1
- https://git.kernel.org/stable/c/92d3817649df2b0b6a008a686c8275c88d7ef594
- https://git.kernel.org/stable/c/c6a13ae00dab3a1a8c7cf2f843f0fc9e8d4b0ccc