SB20260824233 - Out-of-bounds read in Linux kernel ipv6
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74598)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in rt6_route_rcv() when processing a crafted IPv6 Router Advertisement containing a malformed Route Information option. A remote attacker can send a specially crafted Router Advertisement to disclose sensitive information.
When additional options follow the malformed Route Information option, data from the next option can be incorporated into the installed route and become visible to userspace.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b9e02f3bd31c888f2ccdc0ca08e546d6abe9c4d
- https://git.kernel.org/stable/c/2f6f94eda12430fb41b24b44a71e2ea4e93561d7
- https://git.kernel.org/stable/c/3b2231e358d26e3aec5d8040b1fb777af03c5f05
- https://git.kernel.org/stable/c/7309529f257ae18e72112ef9f614edfd6df229bb
- https://git.kernel.org/stable/c/7eac87396c44a312be457ef41d4c5687883be9a2
- https://git.kernel.org/stable/c/d1ad8fb2ac6a1afb71dc22d9ae8efb4dda96c824
- https://git.kernel.org/stable/c/da64ed1f346ba84df574d6469fa2e422b2511719
- https://git.kernel.org/stable/c/ff3cb05289b8a4ef95fa7ea14c7d34818359edbb