SB2026081565 - Race condition in Linux kernel ipv6
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-74398)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a race condition in addrconf_dad_failure in the IPv6 address configuration subsystem when handling duplicate address detection failure processing concurrently with IPv6 address deletion. A local attacker can trigger concurrent state transitions to cause a denial of service.
The issue can lead to a general protection fault when a deleted IPv6 address entry is processed a second time through scheduled DAD work.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3bdc86d89fd6c6523753fa6f42fcfaf30ee699cb
- https://git.kernel.org/stable/c/47b05836705b63dab93d9ac7c69a3a507375ef80
- https://git.kernel.org/stable/c/627ac78f2741e2ebd2225e2e953b6964a8a9182f
- https://git.kernel.org/stable/c/875c284c0f98b042bb97abad460f63a24c977f88
- https://git.kernel.org/stable/c/8ed0ce9ea58d677d1bac92614ee5f60f8ea57363
- https://git.kernel.org/stable/c/b61af0268e3d1308c466bf0be5dced844eafc1ef
- https://git.kernel.org/stable/c/d21be7d051012c6b572fa4e3334443c250216f7b
- https://git.kernel.org/stable/c/e889aa99ad3ed48bb0ddcff6475b17542532d18b