Use-after-free in Linux kernel - CVE-2026-80792
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or cause a denial of service.
The vulnerability exists due to a use-after-free in ip6_finish_output2() when lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE after reallocating the skb head. A local user can trigger IPv6 packet output through an affected lwtunnel transmission path to disclose sensitive kernel data, pollute the neighbour table with arbitrary values, misdirect traffic, or cause a denial of service.
Affected software
How to mitigate CVE-2026-80792
External References
- https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a
- https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862
- https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43
- https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3
- https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a
- https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515
- https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed
- https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e
- https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f