Double free in Linux kernel - CVE-2026-89563
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in ip6_tnl_xmit() when handling errors after expanding packet headroom. A local user can trigger an error after packet headroom expansion to cause a denial of service.
The issue is reachable when collect_md tunnels reject a non-NONE encapsulation type or when ip6_tnl_encap() fails.