Infinite loop in Linux kernel - CVE-2026-63969
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of a stale linked-list state in rt6_fill_node() when walking IPv6 route sibling entries during softirq-side processing. A local user can trigger route state changes to cause a CPU stall.
The issue can result in an infinite loop in the walker.
How to mitigate CVE-2026-63969
Sources
- https://git.kernel.org/stable/c/279853aec9f58d5cd723e6e5617c1c3337b30383
- https://git.kernel.org/stable/c/5e40de719ee76b8d96e2556ce36dbd3bd07bf37d
- https://git.kernel.org/stable/c/9f72412bcf60144f252b0d6205106abf14344abc
- https://git.kernel.org/stable/c/b014a63d2f2c2c767762b548381882dfb1655529
- https://git.kernel.org/stable/c/c65b1f60237daac7c56c2652e064cc566a45dc81
- https://git.kernel.org/stable/c/dc36a04621dcc2447dae428709207810b6c06e14