SB2026100859 - Red Hat Enterprise Linux 9 update for kernel
Published: October 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 38 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-74746)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the netfilter flowtable subsystem when inserting flow tuple nodes into the rhashtable. A remote attacker can trigger garbage collection to observe a partially installed flow to execute arbitrary code.
KASAN reported read and write access to freed slab memory in the flowtable and rhashtable path.
2) Use-after-free (CVE-ID: CVE-2026-64557)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in l2cap_sock_new_connection_cb() in the Bluetooth L2CAP subsystem when handling a newly enqueued child socket reachable through the accept queue after the parent socket lock is released. A remote attacker can trigger a crafted Bluetooth L2CAP connection to execute arbitrary code.
The issue occurs because another task may accept and free the child socket before the callback dereferences it.
3) Improper access control (CVE-ID: CVE-2026-68432)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify VXLAN device configuration across network namespaces.
The vulnerability exists due to improper access control in vxlan_changelink() when handling changelink requests for a VXLAN device whose underlay network namespace differs from the device network namespace. A local privileged user can send a crafted changelink request to modify VXLAN device configuration across network namespaces.
The issue occurs when the caller has CAP_NET_ADMIN in the device network namespace but not in the VXLAN underlay network namespace.
4) Improper access control (CVE-ID: CVE-2026-72052)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify tunnel link configuration across network namespaces.
The vulnerability exists due to improper access control in ip6gre_changelink() and ip6erspan_changelink() when handling changelink requests for devices and tunnel links in different network namespaces. A remote privileged user can send a crafted changelink request to modify tunnel link configuration across network namespaces.
The issue occurs when the device network namespace differs from the tunnel link network namespace, causing capability checks to be applied only to the device namespace.
5) Incorrect calculation (CVE-ID: CVE-2026-72099)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper calculation in dm-integrity when processing integrity metadata tags. A local user can trigger incorrect hash offset handling to cause a denial of service.
6) Race condition (CVE-ID: CVE-2026-72289)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in vgic_prune_ap_list() in the KVM arm64 virtual generic interrupt controller when migrating an interrupt to another vCPU while locks are temporarily dropped. A local user can trigger interrupt migration during this race to cause a denial of service.
The issue can result in list_del() being performed on an interrupt entry that has already been removed from the ap_list.
7) Use-after-free (CVE-ID: CVE-2026-72255)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in nf_queue handling of bridge fake dst references when processing bridged packets queued to NFQUEUE. A local user can queue bridged packets to NFQUEUE during bridge device teardown to cause a denial of service.
The issue affects systems with CONFIG_BRIDGE_NETFILTER enabled and involves queued packets carrying a fake rtable associated with a bridge device.
8) Improper access control (CVE-ID: CVE-2026-74516)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in x2APIC MSR interception handling in KVM SVM/AVIC when AVIC is inhibited while an L2 guest is active. A local user can run a nested guest that triggers this state to cause a denial of service.
The issue can allow an L1 guest to read much of the host APIC state, send arbitrary interrupts, and change task priority before host disruption occurs.
9) Out-of-bounds read (CVE-ID: CVE-2026-74569)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in ct_sip_get_header() in the nf_conntrack_sip SIP connection-tracking helper when processing NAT-rewritten SIP messages over TCP. A remote attacker can send a specially crafted SIP message with a long Contact list to cause a denial of service.
The issue is triggered by integer wraparound in size-change tracking during repeated URI rewriting, which can produce an invalid length value for a subsequent header parse.
10) Stack-based buffer overflow (CVE-ID: CVE-2026-74669)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack out-of-bounds write in ip_vs_in_icmp() when rebasing tunnel ICMP errors and processing IPv4 options. A remote attacker can send a specially crafted ICMP packet with IPv4 timestamp options to cause a denial of service.
The issue is triggered because stale IPv4 option metadata from the outer header is retained after the packet is rebased to the quoted original request.
11) Double free (CVE-ID: CVE-2026-64385)
CWE-ID: CWE-415 - Double Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to double free in SMB2_ioctl() when handling replayable ioctl responses. A remote user can trigger a replayable error condition to cause a denial of service.
12) Use-after-free (CVE-ID: CVE-2026-80792)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or cause a denial of service.
The vulnerability exists due to a use-after-free in ip6_finish_output2() when lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE after reallocating the skb head. A local user can trigger IPv6 packet output through an affected lwtunnel transmission path to disclose sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or cause a denial of service.
13) Improper access control (CVE-ID: CVE-2026-80921)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access a device that is no longer available.
The vulnerability exists due to improper access control in KVM s390 VSIE APCB shadowing when shadowing crypto access bits from a format 0 APCB. A local user can use stale crypto access bits to access a device that is no longer available.
The issue affects nested guest environments.
14) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-89480)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper validation of the received data length in the NVMe/TCP host driver when processing a short C2HData PDU from an NVMe/TCP controller. A remote attacker can respond to a read request with fewer bytes than requested to disclose sensitive information.
15) Improper input validation (CVE-ID: CVE-2026-89481)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in nvme_tcp_handle_r2t() when processing an R2T request for a read command. A remote attacker can send an R2T request for a read command to disclose sensitive information.
The disclosed read destination buffer may contain stale kernel data.
16) Use-after-free (CVE-ID: CVE-2026-89972)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a missing SRCU grace period in the nvme_alloc_ns() error path when concurrently accessing NVMe multipath namespace paths. A remote attacker can trigger concurrent namespace access during error handling to compromise confidentiality, integrity, and availability.
17) Missing Authorization (CVE-ID: CVE-2026-90227)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to write data despite read-only access restrictions.
The vulnerability exists due to missing authorization in the NVME_IOCTL_SUBMIT_IO ioctl handler when submitting NVMe I/O commands. A local user can invoke the ioctl with a crafted I/O command to write data despite read-only access restrictions.
18) Type conversion (CVE-ID: CVE-2026-97417)
CWE-ID: CWE-704 - Type conversion
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger an unaligned memory access.
The vulnerability exists due to an unsafe pointer cast in the tcp_sack() timestamp-only fast path when processing TCP options. A remote attacker can send a TCP packet containing unaligned options to trigger an unaligned memory access.
19) Use-after-free (CVE-ID: CVE-2026-93288)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to failure to wait for an RCU grace period in nfnetlink_log per-network state when processing packets concurrently with network namespace teardown. A local user can trigger concurrent packet processing and network namespace teardown to trigger a use-after-free.
20) Use-after-free (CVE-ID: CVE-2026-53357)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in l2cap_sock_cleanup_listen() and bt_accept_dequeue() in the Bluetooth L2CAP socket handling code when racing listen socket cleanup with a concurrent HCI disconnect. A local user can trigger a listen/close versus HCI-disconnect race to cause a denial of service.
The issue occurs during cleanup of not-yet-accepted child sockets on a listening socket.
21) NULL pointer dereference (CVE-ID: CVE-2026-23442)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in seg6_hmac_validate_skb() and ipv6_srh_rcv() when processing SRv6 paths on a device without IPv6 configuration. A remote attacker can send specially crafted IPv6 traffic to cause a denial of service.
The issue occurs when __in6_dev_get() returns NULL, such as on a device with no IPv6 configuration, including after device unregister or when the MTU is below the IPv6 minimum MTU.
22) Race condition (CVE-ID: CVE-2026-43332)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the thermal zone device registration error path when handling a failed thermal zone device registration after the device has already been registered. A local user can hold a reference to the thermal zone device's kobject to cause a denial of service.
The issue arises if user space obtains a reference before the error path completes, which can lead to premature freeing of the associated thermal zone structure.
23) Improper access control (CVE-ID: CVE-2026-46076)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass hypercall interception controls.
The vulnerability exists due to improper access control in KVM nested SVM handling when processing VMMCALL from an L2 guest. A remote user can invoke an unhandled VMMCALL to bypass hypercall interception controls.
Exploitation requires an active nested virtualization scenario where L2 is running, L1 does not intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is not one of the supported Hyper-V hypercalls.
24) Use-after-free (CVE-ID: CVE-2026-45861)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in qd_put and the gfs2 quota data LRU handling when shutting down the filesystem and the shrinker scans quota data objects. A local user can trigger filesystem shutdown to cause a denial of service.
25) Use-after-free (CVE-ID: CVE-2026-46275)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the hci_uart line discipline lifecycle management when closing or initializing a Bluetooth HCI UART device. A local user can trigger a hangup or race the close and initialization paths to cause a denial of service.
The issue involves workqueue handling and teardown ordering in the close and initialization error paths.
26) Use-after-free (CVE-ID: CVE-2026-46317)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the nested_mmus array in arm64 KVM nested virtualization when reallocating nested MMU structures while the array is being walked under mmu_lock. A local user can trigger nested vcpu initialization and concurrent MMU notifier activity to cause a denial of service.
The issue arises from a race condition between nested vcpu initialization and the MMU notifier path.
27) Out-of-bounds read (CVE-ID: CVE-2026-52942)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in dump_mac_header() in the netfilter nf_log syslog logger when processing an skb sent through AF_PACKET with PACKET_QDISC_BYPASS and an unset MAC header. A local user can send a specially crafted packet to disclose sensitive information.
Only skbs with an unset MAC header are affected.
28) Improper locking (CVE-ID: CVE-2026-53049)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in gfs2_logd() and log flushing functions in the gfs2 log subsystem when handling concurrent transactions. A local user can trigger concurrent log flush activity to cause a denial of service.
29) Out-of-bounds read (CVE-ID: CVE-2026-52986)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the nf_conntrack_sip SIP message parser when parsing non-NUL-terminated SIP packet data containing crafted port values. A remote attacker can send a specially crafted SIP packet to cause a denial of service.
The issue involves port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request(), where parsing could reach the buffer limit without a trailing character.
30) Use-after-free (CVE-ID: CVE-2025-40149)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the tls_device_queue_ctx_destruction() function in net/tls/tls_device.c. A local user can escalate privileges on the system.
31) Improper access control (CVE-ID: CVE-2026-63829)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to modify tunnel configuration across network namespaces.
The vulnerability exists due to improper access control in ipgre_changelink() and erspan_changelink() when handling RTM_NEWLINK changelink requests for GRE tunnel devices. A local privileged user can send a crafted RTM_NEWLINK request to modify tunnel configuration across network namespaces.
The issue occurs when the device network namespace differs from the tunnel link network namespace, because the check was performed only against dev_net(dev).
32) Use of Out-of-range Pointer Offset (CVE-ID: CVE-2026-63924)
CWE-ID: CWE-823 - Use of Out-of-range Pointer Offset
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper pointer handling in the IPv6 extension header parser in net/ipv6/exthdrs.c when processing IPv6 jumbo hop-by-hop options. A remote attacker can send a specially crafted IPv6 packet to cause a denial of service.
33) Use-after-free (CVE-ID: CVE-2026-63922)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a use-after-free risk from stale pointer reuse in ip6_parse_tlv() in net/ipv6/exthdrs.c when parsing IPv6 TLVs containing the HAO option. A remote attacker can send a specially crafted IPv6 packet to cause a denial of service.
The issue occurs when handling a cloned skb where header expansion moves the skb head and invalidates the cached network header pointer.
34) Out-of-bounds read (CVE-ID: CVE-2026-63920)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ip6_datagram_recv_specific_ctl() when processing IPv6 extension headers for recvmsg control messages after the hdrlen field is modified. A local user can use an nftables payload-write expression to corrupt the extension header length and trigger copying beyond the available header data to disclose sensitive information.
Exploitation is reachable from an unprivileged user namespace.
35) Use-after-free (CVE-ID: CVE-2026-63993)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a use-after-free in the vxlan_xmit_one function in drivers/net/vxlan/vxlan_core.c when processing packets after skb_tunnel_check_pmtu() updates the skb head. A local user can trigger the vulnerable code path to execute arbitrary code.
36) Integer overflow (CVE-ID: CVE-2026-63984)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt memory in a forwarded packet.
The vulnerability exists due to an integer overflow in ipv6_rpl_srh_decompress() and ipv6_rpl_srh_rcv() when processing a crafted IPv6 RPL source routing header. A remote attacker can send a specially crafted packet to corrupt memory in a forwarded packet.
The issue occurs because the computed hdrlen value can truncate to zero for a large segment count, causing the compressed header to overlap the decompressed routing data.
37) Out-of-bounds read (CVE-ID: CVE-2026-63992)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iptunnel_pmtud_check_icmp() when processing ICMP packets without a valid transport header. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because the function may be called while the skb transport header is not set.
38) Use-after-free (CVE-ID: CVE-2026-63994)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() when processing tunnel PMTU ICMP and ICMPv6 packet generation. A local user can trigger skb_cow() reallocation while stale network header pointers are still used to cause a denial of service.
Remediation
Install update from vendor's website.