Linux Kernel Vulnerability in IPv6 Routing Mechanism
CVE-2026-74581
What is CVE-2026-74581?
A vulnerability in the Linux kernel's IPv6 routing mechanism allows suppressed routes to potentially leak stale destination data. When a route is suppressed using 'fib6_rule_suppress()', the associated resource pointer can incorrectly reference released routing information, leading to security concerns as later lookups may encounter invalid or stale routes. This can result in unexpected behavior in network routing, potentially impacting system stability and security. The issue has been addressed by ensuring that the resource pointer is cleared when routes are suppressed, preventing leakage of released routes during lookups.
Affected Version(s)
Linux 209d35ee34e25f9668c404350a1c86d914c54ffa < 90c57310e266eb94e4a80d6b15a9ca131d2e82cb
Linux 8ef8a76a340ebdb2c2eea3f6fb0ebbed09a16383 < 5d29b286c9de0b309e94b9ed083aa1a2f429434f
Linux cdef485217d30382f3bf6448c54b4401648fe3f1 < 354db6243eca59e9d187ffbf8b7955b044ce84dc